{
    "1960606": [
        {
            "ioc_value": "94.228.175.10:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:46:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960603": [
        {
            "ioc_value": "91.92.41.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:46:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960604": [
        {
            "ioc_value": "91.92.41.151:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:46:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960605": [
        {
            "ioc_value": "91.92.41.151:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:46:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960602": [
        {
            "ioc_value": "81.168.62.177:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:45:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960601": [
        {
            "ioc_value": "66.253.84.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-11 09:45:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960600": [
        {
            "ioc_value": "5.175.169.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:45:39",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960599": [
        {
            "ioc_value": "46.246.84.3:5064",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:45:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960598": [
        {
            "ioc_value": "37.221.66.206:42069",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-11 09:45:17",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960597": [
        {
            "ioc_value": "217.60.195.157:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:44:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960596": [
        {
            "ioc_value": "216.9.224.115:1254",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:44:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960595": [
        {
            "ioc_value": "194.59.31.206:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:44:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960594": [
        {
            "ioc_value": "186.169.33.116:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:44:13",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960592": [
        {
            "ioc_value": "176.96.137.76:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:44:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960593": [
        {
            "ioc_value": "176.96.137.76:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-11 09:44:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960591": [
        {
            "ioc_value": "144.202.41.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-11 09:43:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960590": [
        {
            "ioc_value": "104.234.177.45:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-11 09:43:12",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960589": [
        {
            "ioc_value": "102.220.161.188:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-11 09:43:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960588": [
        {
            "ioc_value": "4t92b5g6yn.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 09:26:39",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960587": [
        {
            "ioc_value": "ajaib123.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-11 09:20:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0fdf8b638918ac7a04c36e6ea150548dcd245caa8674601c8a9d5905e77f9bc3/",
            "tags": "quasar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960586": [
        {
            "ioc_value": "rtpk86sport-happy.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 09:20:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1960585": [
        {
            "ioc_value": "154.211.86.169:858",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 09:19:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/154.211.86.169",
            "tags": "modat,supershell",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960584": [
        {
            "ioc_value": "45.9.149.180:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-11 09:18:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/45.9.149.180",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960583": [
        {
            "ioc_value": "38.54.110.142:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-11 09:18:28",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/38.54.110.142",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960582": [
        {
            "ioc_value": "35.229.230.203:50051",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-11 09:18:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/35.229.230.203",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960581": [
        {
            "ioc_value": "103.83.86.48:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:17:27",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.48",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960580": [
        {
            "ioc_value": "103.83.86.48:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:17:22",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.48",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960579": [
        {
            "ioc_value": "103.83.86.48:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:17:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.48",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960578": [
        {
            "ioc_value": "103.83.86.40:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:17:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.40",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960577": [
        {
            "ioc_value": "103.83.86.40:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:17:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.40",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960576": [
        {
            "ioc_value": "103.83.86.40:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:17:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.40",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960575": [
        {
            "ioc_value": "103.83.86.126:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:16:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.126",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960574": [
        {
            "ioc_value": "103.83.86.126:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:16:55",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.126",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960573": [
        {
            "ioc_value": "103.83.86.126:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:16:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.126",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960572": [
        {
            "ioc_value": "103.83.86.126:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 09:16:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/103.83.86.126",
            "tags": "modat,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960570": [
        {
            "ioc_value": "69.42.23.214:4732",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nimplant",
            "malware_alias": null,
            "malware_printable": "Nimplant",
            "first_seen_utc": "2026-10-11 09:11:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/69.42.23.214",
            "tags": "modat,nimplant",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960569": [
        {
            "ioc_value": "131.123.43.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nimplant",
            "malware_alias": null,
            "malware_printable": "Nimplant",
            "first_seen_utc": "2026-10-11 09:11:15",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/131.123.43.22",
            "tags": "modat,nimplant",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960568": [
        {
            "ioc_value": "84.31.161.242:8586",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:09:17",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/84.31.161.242",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960567": [
        {
            "ioc_value": "82.131.158.61:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:09:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/82.131.158.61",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960566": [
        {
            "ioc_value": "181.178.164.231:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:09:09",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/181.178.164.231",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960565": [
        {
            "ioc_value": "181.178.164.231:2000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:09:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/181.178.164.231",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960564": [
        {
            "ioc_value": "151.72.106.25:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:09:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/151.72.106.25",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960563": [
        {
            "ioc_value": "14.136.25.30:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:08:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/14.136.25.30",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960562": [
        {
            "ioc_value": "121.45.148.201:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:08:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/121.45.148.201",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960561": [
        {
            "ioc_value": "118.160.40.70:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:08:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/118.160.40.70",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960560": [
        {
            "ioc_value": "109.123.211.81:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:08:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/109.123.211.81",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960559": [
        {
            "ioc_value": "109.123.211.81:10554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 09:08:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/109.123.211.81",
            "tags": "modat,murdoc",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960557": [
        {
            "ioc_value": "49.235.158.141:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-11 09:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960556": [
        {
            "ioc_value": "52.26.225.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 09:04:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/52.26.225.179",
            "tags": "Covenant,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960555": [
        {
            "ioc_value": "50.6.7.9:2078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 09:04:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/50.6.7.9",
            "tags": "Covenant,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960554": [
        {
            "ioc_value": "50.244.103.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 09:04:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/50.244.103.177",
            "tags": "Covenant,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960553": [
        {
            "ioc_value": "50.244.103.177:1311",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 09:04:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/50.244.103.177",
            "tags": "Covenant,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960552": [
        {
            "ioc_value": "191.223.39.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:00:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/191.223.39.70",
            "tags": "asyncrat,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960551": [
        {
            "ioc_value": "157.20.182.15:1338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:00:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/157.20.182.15",
            "tags": "asyncrat,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960550": [
        {
            "ioc_value": "157.20.182.14:1338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:00:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/157.20.182.14",
            "tags": "asyncrat,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960549": [
        {
            "ioc_value": "157.20.182.14:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:00:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/157.20.182.14",
            "tags": "asyncrat,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960548": [
        {
            "ioc_value": "104.243.248.63:3602",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 09:00:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/104.243.248.63",
            "tags": "asyncrat,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960547": [
        {
            "ioc_value": "84.201.6.134:19319",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/84.201.6.134",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960546": [
        {
            "ioc_value": "84.201.6.112:18364",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/84.201.6.112",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960545": [
        {
            "ioc_value": "69.10.46.2:5885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/69.10.46.2",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960544": [
        {
            "ioc_value": "5.61.209.214:13289",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/5.61.209.214",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960543": [
        {
            "ioc_value": "45.143.199.202:4471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/45.143.199.202",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960542": [
        {
            "ioc_value": "204.13.233.138:14036",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/204.13.233.138",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960541": [
        {
            "ioc_value": "2.56.245.38:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/2.56.245.38",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960540": [
        {
            "ioc_value": "195.16.73.86:29284",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/195.16.73.86",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960539": [
        {
            "ioc_value": "194.110.207.202:17310",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:27",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/194.110.207.202",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960538": [
        {
            "ioc_value": "146.103.38.59:28116",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.antidot",
            "malware_alias": null,
            "malware_printable": "Antidot",
            "first_seen_utc": "2026-10-11 08:59:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/146.103.38.59",
            "tags": "antidot,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960537": [
        {
            "ioc_value": "147.93.169.209:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-11 08:58:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/147.93.169.209",
            "tags": "AIRAVAT,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960536": [
        {
            "ioc_value": "140.245.4.86:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-11 08:58:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/140.245.4.86",
            "tags": "AIRAVAT,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960535": [
        {
            "ioc_value": "107.174.241.12:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-11 08:58:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/107.174.241.12",
            "tags": "AIRAVAT,modat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1960534": [
        {
            "ioc_value": "aguiasmarketing.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 08:58:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960533": [
        {
            "ioc_value": "eirena20.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 08:22:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960531": [
        {
            "ioc_value": "turbo-rs.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 08:18:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960532": [
        {
            "ioc_value": "www.seinfor.pe",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 08:18:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960502": [
        {
            "ioc_value": "165.245.250.162:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-11 08:17:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960505": [
        {
            "ioc_value": "130.12.180.212:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:17:05",
            "last_seen_utc": "2026-10-11 08:07:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1960506": [
        {
            "ioc_value": "38.253.224.56:8080",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:17:04",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1960530": [
        {
            "ioc_value": "001f34fdf19d5182498c502703a0bb832d2db88122cf9942eb07f1103fa4e065",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 08:17:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cowrie,script,ssh-honeypot",
            "anonymous": 0,
            "reporter": "Portfwd"
        }
    ],
    "1960529": [
        {
            "ioc_value": "80163426481ee9c85839da927aa861ff55021680a7e836653054bd1092463072",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960528": [
        {
            "ioc_value": "b821afb910005d067ad8ec2708ddb10727db728ccc28958a18f6a240e594af51",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960527": [
        {
            "ioc_value": "d674e3bba48c3f07da03f2f16acecaaf07299922f17ac3c50ed4708bc7c99260",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "cowrie,elf,Gafgyt,honeypot,Mirai,x86-64",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960526": [
        {
            "ioc_value": "690e5586023270cbdf3bbef3a2206d3fb3bce08c5950c81969ab55056f0324bc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960525": [
        {
            "ioc_value": "118385e79114cb138d99509523ec8288069f5a04479428ade0c5b2f95a080b99",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960524": [
        {
            "ioc_value": "9ea1f8e83c99a88df3c938529d76d343cca7fbb37c3948f1560a2b39da2bd4ab",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960523": [
        {
            "ioc_value": "6e28fc6c91da0bd6028f5148f9dfd9ddd873079eb887046d9f309a9b86e61ae4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960522": [
        {
            "ioc_value": "729238bab5e3bb8ada801a6389cf2ebcbf1d6313d772ac20f998771248f9556f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960521": [
        {
            "ioc_value": "de6a0b3f76eda0589d0bcd6f4308f1ba5287acd153b74d2c06af1899dabc0252",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960520": [
        {
            "ioc_value": "863225e8f04a5c54ce5e0581241c8c748a838b7962a811b5ffa5d4eea4370d13",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx,wraith",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960519": [
        {
            "ioc_value": "69c3ce17531000fb71b416fd4f1324a057bcee9ac99180f35fecf32b4091fd9b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx,wraith",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960518": [
        {
            "ioc_value": "3f4a3cbf20414848a9a37f1ac3f642faab9d693b75c3dd1a72fdf336c0ee2ce8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960517": [
        {
            "ioc_value": "7661c8eda1654c01a5d449ff89cd9102d5298aaf74351d13eb29749f471d3b8e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960516": [
        {
            "ioc_value": "e31a8269293613c46da61382464d32102fab048169a326294800f8e322e92fde",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960514": [
        {
            "ioc_value": "7d812a75dce488ce689ef499019828ae566feed61d714a1f9412fdcbb86c129c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960515": [
        {
            "ioc_value": "lckol95734.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 08:12:42",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960513": [
        {
            "ioc_value": "342556e3211ad309b3224fa1e60f4b3dadee88ed10eb268087e05ce07cb9d85a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960512": [
        {
            "ioc_value": "a477d866544abc3f3c3dae9416bd9d91c274253b80c46192b89271caf280b496",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960511": [
        {
            "ioc_value": "48ec51988b1744c1343cfe4570a882526aee5742e15bb147a916979e94d51667",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960510": [
        {
            "ioc_value": "291bbaad9044d17a059cda116b91f9e937c32dba07cc1e484049ecb37d65626d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960509": [
        {
            "ioc_value": "a04b451463f7814783e4d8350ae7aabf27dad1ceb9a7165b22a4cc07aff317b2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,wraith",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960508": [
        {
            "ioc_value": "23b0a91bd40db32e324467945bd595e3bb3d66561949801ec1e931aa36b3f8c4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 08:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960507": [
        {
            "ioc_value": "zj9s97wb.jp168amp-super.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 08:10:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960504": [
        {
            "ioc_value": "103.170.217.147:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-11 08:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960503": [
        {
            "ioc_value": "google-proxy-66-249-84-225.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 07:45:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960499": [
        {
            "ioc_value": "c86b8aa9e16084a67783ec19f6e574abae1413399fc2b219e5a6dfb5e924ea50",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:39:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/c86b8aa9e16084a67783ec19f6e574abae1413399fc2b219e5a6dfb5e924ea50",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960501": [
        {
            "ioc_value": "132.132.140.34.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 07:33:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960500": [
        {
            "ioc_value": "10.243.196.35.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 07:31:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960498": [
        {
            "ioc_value": "qemufipo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 07:30:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960497": [
        {
            "ioc_value": "7aigp3my.lunza.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 07:23:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960496": [
        {
            "ioc_value": "ea9526d87dbfd0900e0e59ea716a484bf1ad2e3bf74f53a514b0999c01bffd29",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-11 07:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "AgentTesla,ps1",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960495": [
        {
            "ioc_value": "a8f4cda11f6719a29959b4ec63a398becbe69d0de9694c1dbb19e8dc56a3d0f2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-11 07:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "AgentTesla,ps1",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960494": [
        {
            "ioc_value": "27d212ef95b9a78deea82c9cf8dc4373c5016da466620b4b5c58ab67962b205f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-11 07:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "AgentTesla,ps1",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960493": [
        {
            "ioc_value": "4ad0587250a223d69ddd122bebbd42b73f5927a431f374e0751e70643d0c0df8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vipkeylogger",
            "malware_alias": null,
            "malware_printable": "VIP Keylogger",
            "first_seen_utc": "2026-10-11 07:12:42",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "keylogger,ps1,VIPKeylogger",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960492": [
        {
            "ioc_value": "https://mathang.club/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-11 07:12:05",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "WARDENStealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960491": [
        {
            "ioc_value": "137.220.153.128:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960490": [
        {
            "ioc_value": "137.220.153.128:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960489": [
        {
            "ioc_value": "137.220.153.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960488": [
        {
            "ioc_value": "137.220.153.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960088": [
        {
            "ioc_value": "https://fh.4-win.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:58",
            "last_seen_utc": "2026-10-11 07:41:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6713982832fdd0efe07912b12c5c5b2b,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960090": [
        {
            "ioc_value": "kelp.camp-cantina.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 07:02:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1960100": [
        {
            "ioc_value": "34c9f78b4ef541baac4a6e84d4f832a7.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:02:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96/behavior",
            "tags": "c2",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1960103": [
        {
            "ioc_value": "605394ec700b60b94fb028048834cb89d7627b35af50382e7f42c5c4c8f61c60",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/605394ec700b60b94fb028048834cb89d7627b35af50382e7f42c5c4c8f61c60",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960104": [
        {
            "ioc_value": "https://217.60.103.161",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:56",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,c73d7597f88e3372738ace4ab1ffa3c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960110": [
        {
            "ioc_value": "192.253.242.39:9985",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-11 07:02:56",
            "last_seen_utc": "2026-10-10 18:30:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Xtreme-PartnerOne",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960113": [
        {
            "ioc_value": "4-win.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/1208c47943cf76a050ee8376cde139d7f2e9ce306af04a986a41ad8d7366b5d5/behavior",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1960114": [
        {
            "ioc_value": "54toto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/1208c47943cf76a050ee8376cde139d7f2e9ce306af04a986a41ad8d7366b5d5/behavior",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1960127": [
        {
            "ioc_value": "0a4578d60bd782b4e589dd85eb08ba64f4b4a24d167ef7d968eaed4411956aeb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/0a4578d60bd782b4e589dd85eb08ba64f4b4a24d167ef7d968eaed4411956aeb",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960128": [
        {
            "ioc_value": "cfc566841ccbd54340b2a1520b2c37d8a494bd8d4964e13738382e8887f0c986",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-11 07:02:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "von"
        }
    ],
    "1960167": [
        {
            "ioc_value": "5b991446073634b7c35c0f9b7e775e7565259ae07dff41215f42e44c39635a87",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/5b991446073634b7c35c0f9b7e775e7565259ae07dff41215f42e44c39635a87",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960318": [
        {
            "ioc_value": "64.91.238.87:2905",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-11 07:02:53",
            "last_seen_utc": "2026-10-11 07:23:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d898365426cdb60a141cbfaa1e6b7e6f,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960319": [
        {
            "ioc_value": "178.16.53.59:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-11 07:02:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960325": [
        {
            "ioc_value": "103.170.217.170:1312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 07:02:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/863225e8f04a5c54ce5e0581241c8c748a838b7962a811b5ffa5d4eea4370d13/",
            "tags": "elf,mirai,sora",
            "anonymous": 0,
            "reporter": "wristhulk"
        }
    ],
    "1960334": [
        {
            "ioc_value": "0890d39cd6af6f3d6d99ae32e4d05649eb472b6d7d5d1726a0473633fe715e5f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/0890d39cd6af6f3d6d99ae32e4d05649eb472b6d7d5d1726a0473633fe715e5f",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960347": [
        {
            "ioc_value": "94.154.43.37:1999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 07:02:52",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "mirai",
            "anonymous": 0,
            "reporter": "seckle"
        }
    ],
    "1960373": [
        {
            "ioc_value": "fable-shine.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960374": [
        {
            "ioc_value": "https://fable-shine.com/curl/g0xsutkb0/iwsnry04os3w6i7z3ufc.dat",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960375": [
        {
            "ioc_value": "https://fable-shine.com/f/9ksbxnvwoj7pts0uxop4sa/01pemlfd",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960376": [
        {
            "ioc_value": "8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960377": [
        {
            "ioc_value": "1d6cd5411bcbfea3f5328b40c62a57b9788a557efc00d927d9d921afe994c19e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960378": [
        {
            "ioc_value": "d1bf789e50cfc13b638867c290f589039eba36f38e3a07aa18ed3ba61e47a80c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960379": [
        {
            "ioc_value": "loop-88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/8d4fc1e1797743dec4c00583dfe989820eb3c2785cf414feaaf440e54719bd6b",
            "tags": "AMOS,ClickFix,Foxveil,macOS",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960383": [
        {
            "ioc_value": "e8ff0ba3bfd76048aca15fb2fc417840ed93991a0e012435e290f520741c523d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/e8ff0ba3bfd76048aca15fb2fc417840ed93991a0e012435e290f520741c523d",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960390": [
        {
            "ioc_value": "e2605e9e08fa9f7b1cc23497fec745f290a97a212cc7056c87459544325ac048",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e2605e9e08fa9f7b1cc23497fec745f290a97a212cc7056c87459544325ac048/",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960392": [
        {
            "ioc_value": "23.100.98.39:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-11 07:02:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "8075,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1960391": [
        {
            "ioc_value": "157.254.167.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-11 07:02:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "17378,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1960393": [
        {
            "ioc_value": "168.245.203.110:3790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.meterpreter",
            "malware_alias": null,
            "malware_printable": "Meterpreter",
            "first_seen_utc": "2026-10-11 07:02:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "58580,c2,censys,metasploit",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1960413": [
        {
            "ioc_value": "176.65.139.231:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:02:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cowrie,elf,Go,honeypot",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1960412": [
        {
            "ioc_value": "38.253.224.56:3778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-11 07:02:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cowrie,elf,Gafgyt,honeypot",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1960414": [
        {
            "ioc_value": "85.137.53.167:25565",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-11 07:02:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "akuma,cowrie,elf,honeypot,Mirai",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1960416": [
        {
            "ioc_value": "2bff53f12b4bd8a1f4a061b849f7f044b1fedc1dc778cda4f15c1897ca9f5d03",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/2bff53f12b4bd8a1f4a061b849f7f044b1fedc1dc778cda4f15c1897ca9f5d03",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960421": [
        {
            "ioc_value": "396cb8333cfb215f01da97994b7fe070c02fd58b80192090d3e52a647b77fd0f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/396cb8333cfb215f01da97994b7fe070c02fd58b80192090d3e52a647b77fd0f",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960424": [
        {
            "ioc_value": "9697dead9eada8f60adf9a7855c8bdf1468f151ebf91089acb1c4bcb52b26aa0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/e1b0abaa-d3d9-4dd9-9d8c-1ab3aee2fd44",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960426": [
        {
            "ioc_value": "cc84973917d7089aa43eab0b5307b1bb052da6c68931be0ba20444a9ae84d9d5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/3ebb5aae-304e-4b04-992b-5becfea7b52b",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960425": [
        {
            "ioc_value": "eec3cf8a0e22c37a3f3faa406d01d5a3d39dedc15de1b60a9947764f1c02d028",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/e1b0abaa-d3d9-4dd9-9d8c-1ab3aee2fd44",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960427": [
        {
            "ioc_value": "a9fc1e7b49f06d3d5161c78da1821de4849de3a9994955e0c9660d14e7031220",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/3ebb5aae-304e-4b04-992b-5becfea7b52b",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960434": [
        {
            "ioc_value": "http://110.42.232.120:8897/?h=110.42.232.120&p=8897&t=tcp&a=a64&stage=true&k=b41bfef6tcp",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd/",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960432": [
        {
            "ioc_value": "http://110.42.232.120:8897/?h=110.42.232.120&p=8897&t=tcp&a=l64&stage=true&k=b41bfef6tcp",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd/",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960435": [
        {
            "ioc_value": "http://110.42.232.120:8897/?h=110.42.232.120&p=8897&t=tcp&a=a32&stage=true&k=b41bfef6tcp",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd/",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960433": [
        {
            "ioc_value": "http://110.42.232.120:8897/?h=110.42.232.120&p=8897&t=tcp&a=l32&stage=true&k=b41bfef6tcp",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd/",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960436": [
        {
            "ioc_value": "http://148.66.17.125:60003/?a=w32&h=148.66.17.125&t=ws_&p=60003",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/3ebb5aae-304e-4b04-992b-5becfea7b52b",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960437": [
        {
            "ioc_value": "2c7a459ee60175bc5c7fad43ab530348af3789d86be558c83e914e126631a803",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/8fc8ae2b-1092-4c00-b86c-88ae03c50809",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960438": [
        {
            "ioc_value": "c9dc947b793d13c3b66c34de9e3a791d96e34639c5de1e968fb95ea46bd52c23",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/8fc8ae2b-1092-4c00-b86c-88ae03c50809",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960439": [
        {
            "ioc_value": "bf8a8241e1d114be03550e909ddb8fb354d84b1e9c1b8a29c809de0160d74ee6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bf8a8241e1d114be03550e909ddb8fb354d84b1e9c1b8a29c809de0160d74ee6/",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960440": [
        {
            "ioc_value": "80f7d2d3de2cdfebab4c9d9b5de17efc7c08de900b12330c349beeaaf3eafedd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 07:02:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bf8a8241e1d114be03550e909ddb8fb354d84b1e9c1b8a29c809de0160d74ee6/",
            "tags": "VShell",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960445": [
        {
            "ioc_value": "wruser.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9a26460e4f8605210d681aebf623588644e9db425ae5d8500c24f2af8aadb506",
            "tags": "RAT,SalatStealer,stealer,WebRat",
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960446": [
        {
            "ioc_value": "salator.es",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9a26460e4f8605210d681aebf623588644e9db425ae5d8500c24f2af8aadb506",
            "tags": "RAT,SalatStealer,stealer,WebRat",
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960447": [
        {
            "ioc_value": "websalat.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9a26460e4f8605210d681aebf623588644e9db425ae5d8500c24f2af8aadb506",
            "tags": "RAT,SalatStealer,stealer,WebRat",
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960448": [
        {
            "ioc_value": "https://gp.4-win.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:31",
            "last_seen_utc": "2026-10-11 07:32:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,c7a50169dbc6d842a7e7d349513f88f1,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960449": [
        {
            "ioc_value": "https://172.104.228.244",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:30",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e76c218ff82c61f1af8c87600d956e3e,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960451": [
        {
            "ioc_value": "187.77.136.206:6902",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-11 07:02:29",
            "last_seen_utc": "2026-10-11 09:15:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "639d58bc468d7960cf903761cf7acf92,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960452": [
        {
            "ioc_value": "https://wssc.flavorroute.cc/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:02:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ef93eae26bdd10fbc5412d5b07706cd91dfe92166cc23cace3901350ac9a92b5/",
            "tags": "HijackLoader,ZigClipper",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960453": [
        {
            "ioc_value": "85dfe92b43734f2573a30e0f295a602111cbcecffc8260534a2f41386a6025d9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 07:02:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ef93eae26bdd10fbc5412d5b07706cd91dfe92166cc23cace3901350ac9a92b5/",
            "tags": "HijackLoader,ZigClipper",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960454": [
        {
            "ioc_value": "13608aa205e934e3e0b3ac504e1589a41285f9197f6f53be01c2bc59f46b6837",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-10-11 07:02:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ef93eae26bdd10fbc5412d5b07706cd91dfe92166cc23cace3901350ac9a92b5/",
            "tags": "HijackLoader,IDATLoader,ZigClipper",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960455": [
        {
            "ioc_value": "ad7ae1df63dc9f6ee4eabbeb4e9c0f98b2a1b1d69ad8bde9b564e998678310c4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-10-11 07:02:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ef93eae26bdd10fbc5412d5b07706cd91dfe92166cc23cace3901350ac9a92b5/",
            "tags": "HijackLoader,IDATLoader,ZigClipper",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960456": [
        {
            "ioc_value": "4323fb90e50b2deb5f9fd235100dd7e41e28f1fd645099dc3bc65e1445463613",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-10-11 07:02:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ef93eae26bdd10fbc5412d5b07706cd91dfe92166cc23cace3901350ac9a92b5/",
            "tags": "HijackLoader,IDATLoader,ZigClipper",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960457": [
        {
            "ioc_value": "82cfa13c5614b24832b396034fdf907a009ab9a9c7a8c77ddc39b66bc66c90d0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.hijackloader",
            "malware_alias": "DOILoader,GHOSTPULSE,IDAT Loader,SHADOWLADDER",
            "malware_printable": "HijackLoader",
            "first_seen_utc": "2026-10-11 07:02:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ef93eae26bdd10fbc5412d5b07706cd91dfe92166cc23cace3901350ac9a92b5/",
            "tags": "HijackLoader,IDATLoader,ZigClipper",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960458": [
        {
            "ioc_value": "862e9cbed9de24b5de5b633e8813af7d1704e95fd22b925e7768e6a151fe9e2a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/862e9cbed9de24b5de5b633e8813af7d1704e95fd22b925e7768e6a151fe9e2a",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960459": [
        {
            "ioc_value": "64.204.180.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9a26460e4f8605210d681aebf623588644e9db425ae5d8500c24f2af8aadb506",
            "tags": "RAT,SalatStealer,stealer,WebRat",
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960464": [
        {
            "ioc_value": "216.86.70.40:2727",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sero_rat",
            "malware_alias": null,
            "malware_printable": "SeroRAT",
            "first_seen_utc": "2026-10-11 07:02:26",
            "last_seen_utc": "2026-10-11 05:56:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/349ef14b-ff7f-4e91-9747-e417ecfbb751",
            "tags": "SeroRAT",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960465": [
        {
            "ioc_value": "d0f2273f828b10391adcf877ff0775924e4b63435ec240b1047d89a1fa95a229",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.sero_rat",
            "malware_alias": null,
            "malware_printable": "SeroRAT",
            "first_seen_utc": "2026-10-11 07:02:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/447e7d5ed5e5bae4d4d34057f2ad9a580583bf363c18befd6c28abec57c0490b/",
            "tags": "SeroRAT",
            "anonymous": 0,
            "reporter": "Daydream"
        }
    ],
    "1960466": [
        {
            "ioc_value": "141.95.112.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/32db4595652db96810710a1c79ecb11d83acd4a4d8ae661e8a430b64a661e14c",
            "tags": "SalatStealer,WebRat",
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960467": [
        {
            "ioc_value": "109.237.98.213:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/32db4595652db96810710a1c79ecb11d83acd4a4d8ae661e8a430b64a661e14c",
            "tags": "SalatStealer,WebRat",
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960468": [
        {
            "ioc_value": "webrat.es",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-11 07:02:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9a26460e4f8605210d681aebf623588644e9db425ae5d8500c24f2af8aadb506",
            "tags": null,
            "anonymous": 0,
            "reporter": "nullos"
        }
    ],
    "1960478": [
        {
            "ioc_value": "https://gp.54toto.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 07:02:22",
            "last_seen_utc": "2026-10-11 06:51:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,c7a50169dbc6d842a7e7d349513f88f1,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960486": [
        {
            "ioc_value": "656c960966c12f507a7d80c59bb377be09ac14c16903f7a933d3ef32a4210c53",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-11 07:02:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/656c960966c12f507a7d80c59bb377be09ac14c16903f7a933d3ef32a4210c53",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960487": [
        {
            "ioc_value": "payload1717.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 06:56:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960485": [
        {
            "ioc_value": "http://saganlive.com:5747",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-11 06:31:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960484": [
        {
            "ioc_value": "ntefk24757.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 06:29:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960483": [
        {
            "ioc_value": "lakyxopa.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 06:21:49",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960482": [
        {
            "ioc_value": "http://59.103.119.88:58644/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-11 06:18:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/59.103.119.88",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1960481": [
        {
            "ioc_value": "proxy-us-east006-cip16.ahrefs.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 06:17:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960480": [
        {
            "ioc_value": "120.26.120.83:9214",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 06:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960479": [
        {
            "ioc_value": "http://arqtsop.shop:9932/reviews",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-11 06:00:07",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960477": [
        {
            "ioc_value": "alladie.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 05:45:22",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c11464f548d27189b733bfb8ecca375d91bf5550b7b51a3962554ab4e74831cb/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960476": [
        {
            "ioc_value": "ufabet88.vip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-11 05:40:17",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/329706c148a26631625f413212a3a09a0c2fbdab23c6ab5f4ba671101a15ecde/",
            "tags": "quasar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960475": [
        {
            "ioc_value": "myquqljcq9.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 05:36:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960474": [
        {
            "ioc_value": "https://web.aloha-hk.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 05:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/web.aloha-hk.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960473": [
        {
            "ioc_value": "uvach.in",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-11 05:10:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/af5b59d2c3af86ee2d97b9bb459dec7b83e5033cfc9b53fb319dbcdddb79e5d5/",
            "tags": "quasar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960472": [
        {
            "ioc_value": "27.50.63.50:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960471": [
        {
            "ioc_value": "199.102.217.211:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-11 05:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960470": [
        {
            "ioc_value": "77-38-104-186.dynamic.telemach.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 04:55:08",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960469": [
        {
            "ioc_value": "77.232.43.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-11 04:47:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960463": [
        {
            "ioc_value": "https://trazoseguro.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 04:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/trazoseguro.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960462": [
        {
            "ioc_value": "ghyu.in",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-11 04:30:21",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/92a4bdc95e0d99200c7e703b2739ffdc1c0dd6b974bd4e97a375ad5a09b1e480/",
            "tags": "quasar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960461": [
        {
            "ioc_value": "qwjq421ff1.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 04:29:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960460": [
        {
            "ioc_value": "kyxyxymo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 04:25:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960450": [
        {
            "ioc_value": "59.220.175.207.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 04:03:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960444": [
        {
            "ioc_value": "ruqegawa.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 03:43:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960443": [
        {
            "ioc_value": "https://taazaproducts.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 03:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/taazaproducts.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960442": [
        {
            "ioc_value": "https://blaze-x.com/Brazzers.msi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 03:08:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960441": [
        {
            "ioc_value": "g5wm6nzi.kulonprogo.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 03:03:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960428": [
        {
            "ioc_value": "101.34.239.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-11 02:44:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960429": [
        {
            "ioc_value": "119.45.12.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-11 02:44:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960430": [
        {
            "ioc_value": "43.136.129.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-11 02:44:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960431": [
        {
            "ioc_value": "82.157.209.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-11 02:44:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960423": [
        {
            "ioc_value": "lovecasino.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-11 02:40:19",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2a0bc1efd509f72273c3f9e3143a3f108edfa4d33dc9c1ba4a86ce362deea86a/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960422": [
        {
            "ioc_value": "3bse5c5d.b00kself.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 02:40:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960420": [
        {
            "ioc_value": "5deeeyo6rt.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 02:37:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960419": [
        {
            "ioc_value": "toqekihe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 02:32:35",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960418": [
        {
            "ioc_value": "posomywu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 02:30:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960417": [
        {
            "ioc_value": "a4b1e1a980e7d870df771f0f9e15a456dce9632ea95fd01a3a9d3ce53adc0b9b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.smartloader",
            "malware_alias": null,
            "malware_printable": "SmartLoader",
            "first_seen_utc": "2026-10-11 02:12:39",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,loader,SmartLoader,trojan,zip",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960415": [
        {
            "ioc_value": "https://orlaproperties.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 02:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/orlaproperties.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960411": [
        {
            "ioc_value": "obrly07273.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 01:47:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960395": [
        {
            "ioc_value": "https://miit-s.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/miit-s.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960396": [
        {
            "ioc_value": "https://comomudarsuamente.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/comomudarsuamente.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960397": [
        {
            "ioc_value": "https://amberbriefs.au/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/amberbriefs.au",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960398": [
        {
            "ioc_value": "https://activesummary.us/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/activesummary.us",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960399": [
        {
            "ioc_value": "https://asongforyou.cool/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/asongforyou.cool",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960400": [
        {
            "ioc_value": "https://deception52.com/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/deception52.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960401": [
        {
            "ioc_value": "https://kohxiv.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/kohxiv.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960402": [
        {
            "ioc_value": "https://www.miei.education/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.miei.education",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960403": [
        {
            "ioc_value": "https://interiorhomedesignsbylianna.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/interiorhomedesignsbylianna.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960404": [
        {
            "ioc_value": "https://parajulis.com.np/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/parajulis.com.np",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960405": [
        {
            "ioc_value": "https://revumaster.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/revumaster.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960406": [
        {
            "ioc_value": "https://tcea.top/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/tcea.top",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960407": [
        {
            "ioc_value": "https://realestateeg.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/realestateeg.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960408": [
        {
            "ioc_value": "https://playasdealmeria.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/playasdealmeria.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960409": [
        {
            "ioc_value": "https://tennis-forecast.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/tennis-forecast.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960410": [
        {
            "ioc_value": "https://bakarmandi.online/?i=1",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-11 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/bakarmandi.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960394": [
        {
            "ioc_value": "google-proxy-66-249-88-104.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 01:21:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960388": [
        {
            "ioc_value": "gp.4-win.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 00:55:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960389": [
        {
            "ioc_value": "https://gp.4-win.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 00:55:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960387": [
        {
            "ioc_value": "www.miei.education",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-11 00:43:05",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960385": [
        {
            "ioc_value": "gp.54toto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 00:40:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960386": [
        {
            "ioc_value": "https://gp.54toto.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-11 00:40:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960384": [
        {
            "ioc_value": "gxpey55565.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 00:38:47",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960382": [
        {
            "ioc_value": "fedane.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-11 00:30:54",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960380": [
        {
            "ioc_value": "http://153.117.66.231:54098/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-11 00:18:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.66.231",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1960381": [
        {
            "ioc_value": "http://118.175.206.237:56655/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-11 00:18:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/118.175.206.237",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1960371": [
        {
            "ioc_value": "https://boxingready.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 23:30:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/boxingready.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960372": [
        {
            "ioc_value": "https://unigadgetz.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 23:30:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/unigadgetz.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960368": [
        {
            "ioc_value": "tcea.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:57",
            "last_seen_utc": "2026-10-11 00:33:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960369": [
        {
            "ioc_value": "tennis-forecast.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:57",
            "last_seen_utc": "2026-10-11 07:32:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960370": [
        {
            "ioc_value": "unigadgetz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:57",
            "last_seen_utc": "2026-10-11 00:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960351": [
        {
            "ioc_value": "activesummary.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960352": [
        {
            "ioc_value": "amberbriefs.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960353": [
        {
            "ioc_value": "asongforyou.cool",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:27:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960354": [
        {
            "ioc_value": "bakarmandi.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:27:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960355": [
        {
            "ioc_value": "boxingready.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:28:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960356": [
        {
            "ioc_value": "comomudarsuamente.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:28:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960357": [
        {
            "ioc_value": "deception52.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:28:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960358": [
        {
            "ioc_value": "dogbraintrainingpro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:28:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960359": [
        {
            "ioc_value": "interiorhomedesignsbylianna.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 00:02:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960360": [
        {
            "ioc_value": "kohxiv.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:28:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960361": [
        {
            "ioc_value": "miei.education",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:29:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960362": [
        {
            "ioc_value": "miit-s.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:29:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960363": [
        {
            "ioc_value": "orlaproperties.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960364": [
        {
            "ioc_value": "parajulis.com.np",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:29:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960365": [
        {
            "ioc_value": "playasdealmeria.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:29:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960366": [
        {
            "ioc_value": "realestateeg.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:31:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960367": [
        {
            "ioc_value": "revumaster.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 23:20:56",
            "last_seen_utc": "2026-10-11 07:30:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960349": [
        {
            "ioc_value": "amberchronicles.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 23:12:02",
            "last_seen_utc": "2026-10-10 23:20:56",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960350": [
        {
            "ioc_value": "agentificial.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 23:12:02",
            "last_seen_utc": "2026-10-10 23:20:56",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960348": [
        {
            "ioc_value": "hgnqp55136.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 23:10:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960346": [
        {
            "ioc_value": "baboa502.rtplive-miliarbet.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 23:07:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960345": [
        {
            "ioc_value": "http://31.77.144.86:49104/ddb64.dll",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 23:07:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "Coinminer,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960344": [
        {
            "ioc_value": "duhygili.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 23:04:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960343": [
        {
            "ioc_value": "138.197.128.142:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-10 22:36:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960342": [
        {
            "ioc_value": "http://hkealop.shop:9932/sessions",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-10 22:35:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960341": [
        {
            "ioc_value": "https://lydigital.com.br/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 22:30:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/lydigital.com.br",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1960340": [
        {
            "ioc_value": "zoastklaeon.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 22:28:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960336": [
        {
            "ioc_value": "analyze-me2.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 22:28:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960337": [
        {
            "ioc_value": "mellow-flicker-comet-pluio.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 22:28:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960338": [
        {
            "ioc_value": "ochre-roam-rook-geoum.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 22:28:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960339": [
        {
            "ioc_value": "poalmcreorvelvet.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 22:28:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1960335": [
        {
            "ioc_value": "nmtjl55277.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 22:23:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960333": [
        {
            "ioc_value": "d14856969df860a679ad1060c7d2a81dd60180d0f5fd22988a4c09de0a6de11b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.smartloader",
            "malware_alias": null,
            "malware_printable": "SmartLoader",
            "first_seen_utc": "2026-10-10 22:12:51",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,loader,SmartLoader,trojan,zip",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960332": [
        {
            "ioc_value": "bafa2a82ec1bf371ef0c28e94730091c43302f50492a72fcc429403ba0889f49",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960331": [
        {
            "ioc_value": "ee08d74477ee187ac5694e07f6deace4f1cec4b8955468df9cc9059ee20bc63f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960330": [
        {
            "ioc_value": "e81982006eb1a6643b10b103c8e94b5ee63d6ef293cc21d53a2b3ba9a93ba0fa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960329": [
        {
            "ioc_value": "972a8e1eb9cfa81b96888ba74120917eed6a2d9c9b77c4de8105026e4fc04787",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960328": [
        {
            "ioc_value": "f4e87418b810b69cf43ef33d876c7b119718f15a3cbc8562e344c32a74e2c26c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960327": [
        {
            "ioc_value": "cb4c28fdc8a1bc5671a48cd81c5aac5438d64001ca1ad2a2ef6b133d3c79493a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960326": [
        {
            "ioc_value": "cbdb650d0d991d2102d4bbe24130c63130908c0e50ee381c4c9ca495d4cdf08c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 22:12:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960324": [
        {
            "ioc_value": "3cipm334.pilkada2017.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 21:33:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960321": [
        {
            "ioc_value": "apinetsolworkspace.network",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-10 21:33:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960322": [
        {
            "ioc_value": "devicehubcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-10 21:33:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960323": [
        {
            "ioc_value": "blackcryptknight.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-10 21:33:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960320": [
        {
            "ioc_value": "ciluzo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 21:17:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960317": [
        {
            "ioc_value": "jaiij24682.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 21:10:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960315": [
        {
            "ioc_value": "ae5ed7c741695e76561ef0b66b1792fc95a5d1d4",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.deltastealer",
            "malware_alias": null,
            "malware_printable": "DeltaStealer",
            "first_seen_utc": "2026-10-10 21:09:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960316": [
        {
            "ioc_value": "2ce0c7b067339c33da3ae88154d0a6b2",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.deltastealer",
            "malware_alias": null,
            "malware_printable": "DeltaStealer",
            "first_seen_utc": "2026-10-10 21:09:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960314": [
        {
            "ioc_value": "d61419108785340e5b48fb4ef5fec85f46bbeaa86636bdfa9706b7df16a2e0f4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.deltastealer",
            "malware_alias": null,
            "malware_printable": "DeltaStealer",
            "first_seen_utc": "2026-10-10 21:09:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960311": [
        {
            "ioc_value": "a79c713bfb2f0ca6c6eed68466723a5d24d2fcead39b7d2aeff262083909efd0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-10-10 21:09:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960312": [
        {
            "ioc_value": "97dbb5bf65426b00a0e42ca86519018a2982c0b1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-10-10 21:09:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960313": [
        {
            "ioc_value": "6d82907be55d8d627bbd17e70f4846ac",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-10-10 21:09:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960308": [
        {
            "ioc_value": "dfc1236ffc512053310826982da37c5fe9cf2fd73847e2c9f0fdc52497de5066",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:09:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960309": [
        {
            "ioc_value": "fbe24aeef1b7021d41b0949c126860e303d92706",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:09:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960310": [
        {
            "ioc_value": "e7a99c961596ae02b33bba60829df743",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:09:13",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960305": [
        {
            "ioc_value": "cf03c5920933f4c0f79c71e52edb28d238bb8396e71558ecc9b33a595fc0a9ae",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:09:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960306": [
        {
            "ioc_value": "0c77484252a50e76e06efd8d53cbec7a71397c2e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:09:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960307": [
        {
            "ioc_value": "31525df166ed1ca0a0da57f68b2fbb3e",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:09:12",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960302": [
        {
            "ioc_value": "6e13203eb73938e8685388a45968ef00",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:09:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960303": [
        {
            "ioc_value": "0ce2616101d746cfdd3d0ba294666a2a41443160",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:09:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960304": [
        {
            "ioc_value": "9c2d17c7cf9be978bb06c9ac20365293",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:09:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960298": [
        {
            "ioc_value": "25fd875e077d212ed298f53a549c98f63490aa4d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-10 21:09:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960299": [
        {
            "ioc_value": "fae31a1b99b802d086777002b8e1d513",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-10 21:09:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960300": [
        {
            "ioc_value": "2f70cfcee962a80007a5f3b6441e5bb0a25ac7398cfcca5ab87caf65c05e9e71",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:09:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960301": [
        {
            "ioc_value": "3895a3afa2a234755e467a32590a26028933eeb0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:09:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960295": [
        {
            "ioc_value": "c4bb3e578b038fdd3986e5edb6b9a09e475c2cdf",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-10 21:09:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960296": [
        {
            "ioc_value": "fc2f1cdd2fbb4061a8f9e909c64b7f54",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-10 21:09:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960297": [
        {
            "ioc_value": "489109095909eb9b3d60db1a01178080073b068e535735a026d351d446bef1d2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-10 21:09:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960291": [
        {
            "ioc_value": "950eb350edf0887058c64221846564f054d8ace58b504abd6b97ba3ce45c66e2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quantloader",
            "malware_alias": null,
            "malware_printable": "QuantLoader",
            "first_seen_utc": "2026-10-10 21:09:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960292": [
        {
            "ioc_value": "d26d8c35d534f72ea44f1e7a71db4cdcf3ec4f34",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quantloader",
            "malware_alias": null,
            "malware_printable": "QuantLoader",
            "first_seen_utc": "2026-10-10 21:09:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960293": [
        {
            "ioc_value": "6e4188eab774c2d0641bfcb032f19799",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quantloader",
            "malware_alias": null,
            "malware_printable": "QuantLoader",
            "first_seen_utc": "2026-10-10 21:09:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960294": [
        {
            "ioc_value": "9fe84328554e02c9aae80f9fda0fb6c06e8b16bde91f6070a991a619bfc61238",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-10 21:09:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960288": [
        {
            "ioc_value": "d2b5f4ff9ccf98b4ebff54c8bf85e242bcf2b6387c10c451fe8c21d73c5d24fc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.moriagent",
            "malware_alias": null,
            "malware_printable": "MoriAgent",
            "first_seen_utc": "2026-10-10 21:09:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960289": [
        {
            "ioc_value": "8d925835f2eb0d742d098b2a4ed92f8d19f1ba41",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.moriagent",
            "malware_alias": null,
            "malware_printable": "MoriAgent",
            "first_seen_utc": "2026-10-10 21:09:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960290": [
        {
            "ioc_value": "f0af25e9b2ac985a1ba4eba7ca321806",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.moriagent",
            "malware_alias": null,
            "malware_printable": "MoriAgent",
            "first_seen_utc": "2026-10-10 21:09:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960284": [
        {
            "ioc_value": "82967b6c24f52664a3b9399f853ea812",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:09:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960285": [
        {
            "ioc_value": "45b8c5064a92c60ea747e3bdd7dbe201fe8577942c048f1e942e9237e3b9a6ec",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-10-10 21:09:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960286": [
        {
            "ioc_value": "c4404f65fe9d57709f0a0387fe1dd741e1b8fbc3",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-10-10 21:09:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960287": [
        {
            "ioc_value": "8d1d55cdb009796323a6ffe8c3403795",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-10-10 21:09:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960281": [
        {
            "ioc_value": "fedaf63f737fd855505e9c11fb0458f765df4fa5",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.tinymet",
            "malware_alias": "TiniMet",
            "malware_printable": "TinyMet",
            "first_seen_utc": "2026-10-10 21:09:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960282": [
        {
            "ioc_value": "8c37e43091ae6750e9dd459f81f0f32c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.tinymet",
            "malware_alias": "TiniMet",
            "malware_printable": "TinyMet",
            "first_seen_utc": "2026-10-10 21:09:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960283": [
        {
            "ioc_value": "064e83897c545f71f2f6a879ea0845f6d23ec9b9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:09:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960278": [
        {
            "ioc_value": "7eabb4b11cb6f4182396c78255edda5074c092de",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960279": [
        {
            "ioc_value": "f0a5f859bf11fb59dfc898cfff1d3a57",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960280": [
        {
            "ioc_value": "01805651d30a44df6d53dd07e5813e6be2a9b496f9568da8ab4d443e9db7bde6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.tinymet",
            "malware_alias": "TiniMet",
            "malware_printable": "TinyMet",
            "first_seen_utc": "2026-10-10 21:09:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960276": [
        {
            "ioc_value": "475af0075ebbfbe9095714354ba8bde1351fd385",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960277": [
        {
            "ioc_value": "a5836555b66a6cf07bae480d0784c0d6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960273": [
        {
            "ioc_value": "fda3692724e2f52fbbf34be12dfcc6f9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:02",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960274": [
        {
            "ioc_value": "835f9ab526c8ee4208f701c438c68b09b1c54f43",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:02",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960275": [
        {
            "ioc_value": "79b6b834125fa351b72ded1aefe2f199",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:02",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960271": [
        {
            "ioc_value": "2e1472c57f6a711c2c6b7602221b86c5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960272": [
        {
            "ioc_value": "e966868ffab340f5cdac01698e4a63373a188e87",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960268": [
        {
            "ioc_value": "64d38238ca7f5ce2e0f8cd8b798df7b155a323e8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960269": [
        {
            "ioc_value": "c002f45ab245cbcbd0386560b071f581",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960270": [
        {
            "ioc_value": "a07181a77656045e86bdbac5b47bcfcc238fefe8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:09:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960266": [
        {
            "ioc_value": "5a4190498353e731e500700e2360bf2e65c0ce6b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960267": [
        {
            "ioc_value": "baf8a415b418e178fa5bdca17ca20180",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960263": [
        {
            "ioc_value": "6b9c3b61a843c55da3a53b548161c168",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960264": [
        {
            "ioc_value": "a875d507c65bea54c7ef8d0bfb31cac167876896",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960265": [
        {
            "ioc_value": "7031764d914024a88fe83299f2fafd98",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960262": [
        {
            "ioc_value": "96a73db615df39ba34bc05cb4864f65370c64941",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960260": [
        {
            "ioc_value": "16208b880eb6fd96a604f64811008f51b3264892",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960261": [
        {
            "ioc_value": "d8b77b37a651aa029928aaa83763407d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960258": [
        {
            "ioc_value": "dc66f24dcb9c159c8e5bebb53ce9c4bf7f9f974c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960259": [
        {
            "ioc_value": "e96d4af3d295cc1f2e07411c26758153",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960255": [
        {
            "ioc_value": "413af1f553721dae4996d11ac19f2978",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960256": [
        {
            "ioc_value": "b38b68931a8607e1f78f00188843fdd4a4ee60b0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:08:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960257": [
        {
            "ioc_value": "e44b8803d57a6bc4a3561f61b95ff731",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:08:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960254": [
        {
            "ioc_value": "de4c0f3d7bbe082030ec6cf06c1e8e6b75e382dc",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960251": [
        {
            "ioc_value": "9b11e6ed6a0687ef06fe3a73dc16b4ec",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960252": [
        {
            "ioc_value": "1ebc567f0f84bc27db5a031e90c988dcac86bf8a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960253": [
        {
            "ioc_value": "f2041ff2f92ccfe3775f1507dbb087d9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960250": [
        {
            "ioc_value": "cbf13492eb04c76f48354ee946e9a91b6a21e890",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960248": [
        {
            "ioc_value": "426592ad06d9af565a5be17c2e4587375f0db704",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960249": [
        {
            "ioc_value": "4fdcf56964bbc3a2c9848c05f00f9b56",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960247": [
        {
            "ioc_value": "b068f38757134531bcb0489d96324ae0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:49",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960246": [
        {
            "ioc_value": "11098dacda6ba8520fcf815b9b40bc687137a386",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960245": [
        {
            "ioc_value": "0b9dbdb9290c53fd7f7f070f5bec478b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.mirai",
            "malware_alias": null,
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 21:08:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960243": [
        {
            "ioc_value": "523d561061c3fea9c863a15c61042897",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960244": [
        {
            "ioc_value": "faf49c397f2b88ad54175226644887f3f5160f89",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.mirai",
            "malware_alias": null,
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 21:08:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960241": [
        {
            "ioc_value": "8e5999ff4481cd73e6a74df6f4d60af1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960242": [
        {
            "ioc_value": "b2197fbbe510da4d73032a68f72607623f804dfd",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:45",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960240": [
        {
            "ioc_value": "c9bfc0495da0b9268153816a4ebc9cabe8a6ccfb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:44",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960239": [
        {
            "ioc_value": "2c252bc8ecf99d3659df65af554c0c4d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-10 21:08:43",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960238": [
        {
            "ioc_value": "c9acfe5840c11b540ae2c1959e68d68c880c7d28",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-10 21:08:42",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960235": [
        {
            "ioc_value": "92891caa5f220f8251a7b0e7b827d47a0493ce50",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960236": [
        {
            "ioc_value": "0e32c55428f531e7c09b476f42c0cfc1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960237": [
        {
            "ioc_value": "11862191bdcfc8bb03d5e7e1f72a1db133eaaca9344916a6c79c3517f7aba06d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-10 21:08:41",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960233": [
        {
            "ioc_value": "e8ef5d81fcf677ad613ecf75975d2b6785cd68f2",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960234": [
        {
            "ioc_value": "1de007ec15884a623391a3b13cb4596b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:40",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960232": [
        {
            "ioc_value": "5d98562f29a6e4197c43d1db35192118",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:38",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960231": [
        {
            "ioc_value": "43f4a114f561f14674e41819a6343ae15f17668d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960229": [
        {
            "ioc_value": "619d11577b3ae4fb569856b132a4220ac4651489",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.babadeda",
            "malware_alias": null,
            "malware_printable": "Babadeda",
            "first_seen_utc": "2026-10-10 21:08:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960230": [
        {
            "ioc_value": "c2ab98b7da779932e8fa25a279e59a8c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.babadeda",
            "malware_alias": null,
            "malware_printable": "Babadeda",
            "first_seen_utc": "2026-10-10 21:08:36",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960226": [
        {
            "ioc_value": "5528b5e88656593ef5c680980621855ef84389efd06fb441a01ff3b48d8bdeb9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.purecrypter",
            "malware_alias": null,
            "malware_printable": "PureCrypter",
            "first_seen_utc": "2026-10-10 21:08:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960227": [
        {
            "ioc_value": "53d00c1228f702931ff7b4e55cdb433858edd491",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.purecrypter",
            "malware_alias": null,
            "malware_printable": "PureCrypter",
            "first_seen_utc": "2026-10-10 21:08:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960228": [
        {
            "ioc_value": "c6077f50c2ccb6e4b9263222adcc223e",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.purecrypter",
            "malware_alias": null,
            "malware_printable": "PureCrypter",
            "first_seen_utc": "2026-10-10 21:08:35",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960224": [
        {
            "ioc_value": "24f8618ede8ebf037ca603114b5d917bd5c9966b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960225": [
        {
            "ioc_value": "2986bdb8dd1f62b11c1c57e58f00ae50",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:34",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960222": [
        {
            "ioc_value": "16687cfe65c4d3598ca0a880f9b0fca0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960223": [
        {
            "ioc_value": "4dbc2a3dcbd0a5a711f45789a4367cd959fc0dcc37ddc1d6e335cb98925aa688",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:33",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960219": [
        {
            "ioc_value": "e7c45671c68e5100f7191de9106af5a8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960220": [
        {
            "ioc_value": "b6ea43e7f0371f5278f7d56dbdea7da203fe51976f5ea3751aff0598d44d8921",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960221": [
        {
            "ioc_value": "980d8ddf9c7882ea0703b88c527ea4e5135bf994",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:32",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960215": [
        {
            "ioc_value": "19a5d6aa69f753aa541f7797cc8538b63f11ef0a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:31",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960216": [
        {
            "ioc_value": "79af7efda58aaa0562bbd3b98ae65a18",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:31",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960217": [
        {
            "ioc_value": "ac97ff69a8b5da0b04c14ed85945931c6218823d829192f2d7bcfa022b6b65b9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:31",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960218": [
        {
            "ioc_value": "1d789d594126b9cfd934dc99dcb89ad5f012a869",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:31",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960213": [
        {
            "ioc_value": "dfe0826ecc3baeb9e74e361adbcd34bd",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:30",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960214": [
        {
            "ioc_value": "ad10f4c694e060e8cf9066c8156e03c3eef0a413c125c51e64baceca732c4f31",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 21:08:30",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960209": [
        {
            "ioc_value": "83bd590fbc2fa412433e6bd76fee16b379ac6557",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-10 21:08:29",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960210": [
        {
            "ioc_value": "56e705cf656cce54945c7941442a6624",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-10 21:08:29",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960211": [
        {
            "ioc_value": "79ada3e5bddf5a6ffb1977e4e0f50a13512a02e2ba786b96b86190498d175873",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:29",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960212": [
        {
            "ioc_value": "06277d663bba5b94d3c968c263eaf257c307de92",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 21:08:29",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960207": [
        {
            "ioc_value": "a6a09b6e372bf40b716d2bf3237c2902",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 21:08:28",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960208": [
        {
            "ioc_value": "77415566cdc9a0f0d16347961f5eacca934a73cb4e00c834b782962e9de8d417",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-10 21:08:28",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960204": [
        {
            "ioc_value": "df6f9ce4475da25b324829509ef5c186",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 21:08:27",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960205": [
        {
            "ioc_value": "26acdf091d7a9bcf72b056561bc69221de623d43097499a777f59cab859b88a1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 21:08:27",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960206": [
        {
            "ioc_value": "5d5c5f7e3be6c4e74de331adfdbb17a62ef2ab9a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 21:08:27",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960200": [
        {
            "ioc_value": "541585f6e692ebb31978db80267944853067af4c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-10-10 21:08:26",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960201": [
        {
            "ioc_value": "2c9056c7f596f9e135ae1fe685b42f87",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-10-10 21:08:26",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960202": [
        {
            "ioc_value": "d5102a93f27c365d5a1d57e82d0d4571d558ff846c50efd7896905fc736148ea",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 21:08:26",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960203": [
        {
            "ioc_value": "906a01862b47d1cac17b33ffa9e4074375aeb902",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 21:08:26",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960196": [
        {
            "ioc_value": "cfbd859dc82f8bd3af2c90598a9d46145f6dc4b3663de9e5195812519ab09948",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:08:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960197": [
        {
            "ioc_value": "001c8845650edf9d21aff64a566f43f3ffd2bce3",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:08:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960198": [
        {
            "ioc_value": "ea6af616eb4cb6efd68dc8140db720b0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:08:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960199": [
        {
            "ioc_value": "9b4bfdddc2a1a59cf45915fd20f183afb6a255575bb646441d821622600cd223",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-10-10 21:08:25",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960192": [
        {
            "ioc_value": "25a7c4a7d8ca13429745d57f052401f7",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "osx.orat",
            "malware_alias": null,
            "malware_printable": "oRAT",
            "first_seen_utc": "2026-10-10 21:08:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960193": [
        {
            "ioc_value": "10e851bd7fc8e17b390cb8ccedb4becbe1008ff37e6b327c761b2572f42ea5ab",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:08:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960194": [
        {
            "ioc_value": "1f5d57b0c478706a4033cfbf34ce1c315f31e794",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:08:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960195": [
        {
            "ioc_value": "a2c0862d74a77d74b4d5c945a994cba3",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-10 21:08:24",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960189": [
        {
            "ioc_value": "263ca98327e452380ea330c8a9a5664f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:23",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960190": [
        {
            "ioc_value": "447e7d5ed5e5bae4d4d34057f2ad9a580583bf363c18befd6c28abec57c0490b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.orat",
            "malware_alias": null,
            "malware_printable": "oRAT",
            "first_seen_utc": "2026-10-10 21:08:23",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960191": [
        {
            "ioc_value": "213ab74d392e00fc5de6d51d8ad87e7b05a718a1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "osx.orat",
            "malware_alias": null,
            "malware_printable": "oRAT",
            "first_seen_utc": "2026-10-10 21:08:23",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960186": [
        {
            "ioc_value": "bb65215c42767d9a7f3943a024e39ef9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:22",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960187": [
        {
            "ioc_value": "dec381ad98ee824cd95313883bc4a17244e8c3a4f37de3b0354fb9f636b2134b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:22",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960188": [
        {
            "ioc_value": "67c19625d6d52067318ce6b55557574b63b2b2e8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:22",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960183": [
        {
            "ioc_value": "fee6d07c0dfef6724ba1646362fb7c4c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960184": [
        {
            "ioc_value": "e58536bb0fb12bfe4253f44f46f4aedbdaa37d195c31d1976e8cb78e925f1d76",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960185": [
        {
            "ioc_value": "89b3a2807a2c675cb7948c9318184fe3491bb64f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:21",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960179": [
        {
            "ioc_value": "57006007128e2fe3236d91efeaf80cc654658998",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.recordbreaker",
            "malware_alias": null,
            "malware_printable": "RecordBreaker",
            "first_seen_utc": "2026-10-10 21:08:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960180": [
        {
            "ioc_value": "5f3be9263a702f55f2f43782882bf3de",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.recordbreaker",
            "malware_alias": null,
            "malware_printable": "RecordBreaker",
            "first_seen_utc": "2026-10-10 21:08:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960181": [
        {
            "ioc_value": "e9f75925a4da2748957701e7a8b25b0b9e724fd86a7d603d099d918f3b34e19a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960182": [
        {
            "ioc_value": "e2a599f4e173a8c358b49361757aa100fe182275",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-10 21:08:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960178": [
        {
            "ioc_value": "e7103164b532a7e095f652e9f6a93a9e929eae88a4022e34c5eed980c65c3d34",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.recordbreaker",
            "malware_alias": null,
            "malware_printable": "RecordBreaker",
            "first_seen_utc": "2026-10-10 21:08:19",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960174": [
        {
            "ioc_value": "e6bd58f332c9aabe502e35ccedb38313",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-10-10 21:08:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960175": [
        {
            "ioc_value": "bc4585a4cce1a946b4f83a887c627af6b4e6b45e1daa493cf3f117e180250813",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-10 21:08:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960176": [
        {
            "ioc_value": "dd1676899b9a43d61fcd2ee16e84be04444cc0cc",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-10 21:08:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960177": [
        {
            "ioc_value": "e44a70b628c96e4621411e51691422b1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-10 21:08:18",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960171": [
        {
            "ioc_value": "070c2cc17d3f0c3086f6410df6886a6b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:08:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960172": [
        {
            "ioc_value": "44cd0e97316c4ed137b1612e5b4d56f7caaa0250d3badbb344927671a6979714",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-10-10 21:08:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960173": [
        {
            "ioc_value": "a4c1719efe4255d5c34366b87e0046c3864c0c15",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.ghost_rat",
            "malware_alias": "Farfli,Gh0st RAT,PCRat",
            "malware_printable": "Ghost RAT",
            "first_seen_utc": "2026-10-10 21:08:17",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960169": [
        {
            "ioc_value": "87d8778250a4515ed73221ba47fb861ac9fb0303c49045dd9f5cc6954021477a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:08:16",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960170": [
        {
            "ioc_value": "5c6c793ed469e95cb67f4389db9d1b41a7c35bf0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 21:08:16",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1960168": [
        {
            "ioc_value": "https://sosaiem217.pages.dev/Sosaiem-Miner.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 21:05:39",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": true,
            "reference": null,
            "tags": "coinminer,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960166": [
        {
            "ioc_value": "188.166.229.242:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-10 20:32:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960164": [
        {
            "ioc_value": "narrowhelyn.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 20:27:46",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960163": [
        {
            "ioc_value": "csgroup.zip",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 20:27:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960162": [
        {
            "ioc_value": "csgroup.zip",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 20:27:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960161": [
        {
            "ioc_value": "242594ab43c445a116b0fd835a811696c179a5cbffbf0df8ca4a0e99c0b5682f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960160": [
        {
            "ioc_value": "b7e704d90e6281d4ef4b0fcdbb06bf3733435e7a3d473668713149bae76f2abe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960159": [
        {
            "ioc_value": "17e6710b264fd0c0b9b90457359c48bee27befd92132637e0ce4551218cc54c4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960158": [
        {
            "ioc_value": "3568368d5a6a3edb7abd622340f9c87a73a2ac143d30e236ce7bd5b27a91e3bb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960157": [
        {
            "ioc_value": "82c3911a4b2a559118471c87cfbbf38211020c42f3d77c77a6bfb9a2c9012b46",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960156": [
        {
            "ioc_value": "d3e89dc4da146c03e18f4cc93ffd9d1738ff73be1876900ee44c0e7be416382e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960155": [
        {
            "ioc_value": "bd9ac14ea870f3659a3e99718e00aa118b69e736fa783fd196737aa80ae205eb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960154": [
        {
            "ioc_value": "2631e628a204008b27b5956b90d40d66799d663731331ab09b3f0bb77c645100",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960153": [
        {
            "ioc_value": "ede4c9a228a124b0735b72fffe9121596c184b676bdc298dfe4ad5b77421cd12",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960152": [
        {
            "ioc_value": "f602c9b0ff36b90c47d65c788200c7d62e898717f1c041848c68e5a07c79ccce",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960151": [
        {
            "ioc_value": "7bdb2edff669a7dc719ba30b25d350513b463a19ea0409721f6f83bdf41af795",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960150": [
        {
            "ioc_value": "1f7bd959e17b09986e17291aae498a251dab8927f14d38045729f600f29ab3b4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960149": [
        {
            "ioc_value": "fc07fe31dfb51b568db664cf84653e37d223ad7587f6a65934435a3762d308d5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 20:12:37",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960148": [
        {
            "ioc_value": "94.154.43.64:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-10 19:45:55",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960147": [
        {
            "ioc_value": "91.92.41.151:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:45:52",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960146": [
        {
            "ioc_value": "89.47.99.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 19:45:49",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960145": [
        {
            "ioc_value": "82.26.66.167:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:45:45",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960144": [
        {
            "ioc_value": "78.71.213.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 19:45:42",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960142": [
        {
            "ioc_value": "46.246.84.3:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 19:45:26",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960143": [
        {
            "ioc_value": "46.246.84.3:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 19:45:26",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960141": [
        {
            "ioc_value": "45.192.211.91:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:45:18",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960139": [
        {
            "ioc_value": "217.60.77.63:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:44:55",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960140": [
        {
            "ioc_value": "217.60.77.63:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:44:55",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960137": [
        {
            "ioc_value": "217.60.102.74:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:44:51",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960138": [
        {
            "ioc_value": "217.60.102.74:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:44:51",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960135": [
        {
            "ioc_value": "216.9.224.115:1250",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 19:44:49",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960136": [
        {
            "ioc_value": "216.9.224.115:1252",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 19:44:49",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960134": [
        {
            "ioc_value": "20.98.57.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-10 19:44:26",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960133": [
        {
            "ioc_value": "2.56.166.25:45391",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-10 19:44:23",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960131": [
        {
            "ioc_value": "194.59.31.175:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:44:18",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960132": [
        {
            "ioc_value": "194.59.31.175:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:44:18",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960130": [
        {
            "ioc_value": "192.154.225.35:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 19:44:12",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960129": [
        {
            "ioc_value": "176.96.137.76:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 19:43:58",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960125": [
        {
            "ioc_value": "tr.4-win.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 19:25:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960126": [
        {
            "ioc_value": "https://tr.4-win.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 19:25:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960123": [
        {
            "ioc_value": "tr.54toto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 19:20:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960124": [
        {
            "ioc_value": "https://tr.54toto.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 19:20:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960122": [
        {
            "ioc_value": "aidigi.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 19:16:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1960121": [
        {
            "ioc_value": "fmbaj52595.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 19:15:32",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960120": [
        {
            "ioc_value": "82.202.157.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-10 19:05:07",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960119": [
        {
            "ioc_value": "49.235.158.141:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 19:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960118": [
        {
            "ioc_value": "245.178.156.34.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 19:02:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960116": [
        {
            "ioc_value": "e-learning.fly-and-film.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 18:53:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960117": [
        {
            "ioc_value": "awtad.biz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 18:53:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960115": [
        {
            "ioc_value": "16t38k5v.rtp-k86sportop.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 18:45:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960112": [
        {
            "ioc_value": "159.89.196.255:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-10 18:32:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1960111": [
        {
            "ioc_value": "nekizuzy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 18:28:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960109": [
        {
            "ioc_value": "http://202.47.49.125:56345/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 18:18:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/202.47.49.125",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1960108": [
        {
            "ioc_value": "http://45.2.24.40:59399/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 18:18:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/45.2.24.40",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1960107": [
        {
            "ioc_value": "e23723b0b476a2b6d8f8ac544e4872e0cb2c6beec35d735bc8d2296dc37c6387",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 18:12:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960105": [
        {
            "ioc_value": "nz.54toto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 18:10:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960106": [
        {
            "ioc_value": "https://nz.54toto.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 18:10:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960102": [
        {
            "ioc_value": "a2czenco6n.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 17:25:29",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960101": [
        {
            "ioc_value": "hesadyse.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 17:18:30",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960099": [
        {
            "ioc_value": "http://208.167.245.124:18884/?h=208.167.245.124&p=18884&t=ws&a=w64&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 17:10:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960098": [
        {
            "ioc_value": "http://208.167.245.124:18884/?h=208.167.245.124&p=18884&t=ws&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 17:10:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960097": [
        {
            "ioc_value": "http://208.167.245.124:9993/?h=208.167.245.124&p=9993&t=tcp&a=w64&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 17:09:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960096": [
        {
            "ioc_value": "http://208.167.245.124:9993/?h=208.167.245.124&p=9993&t=tcp&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 17:08:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960095": [
        {
            "ioc_value": "http://208.167.245.124:18884/?h=208.167.245.124&p=18884&t=tcp&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 17:08:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960094": [
        {
            "ioc_value": "https://pulse-dtc.pages.dev/download/pulse-installer.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 17:06:31",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": true,
            "reference": null,
            "tags": "exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960093": [
        {
            "ioc_value": "http://91.92.242.236/files-129312398/files/file_a6357da6a05d7266.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 17:06:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "54e64e,dropped-by-Amadey,exe,spyware",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960092": [
        {
            "ioc_value": "http://91.92.242.236/files-129312398/files/file_37b904483beaa60e.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-10 17:06:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "54e64e,dropped-by-Amadey,dropper,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960091": [
        {
            "ioc_value": "http://77.237.29.219:2027//sshd",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.sshdoor",
            "malware_alias": null,
            "malware_printable": "SSHDoor",
            "first_seen_utc": "2026-10-10 17:06:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "elf,SSHdKit,SSHDoor",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960089": [
        {
            "ioc_value": "kelp.camp-cantina.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 17:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1960087": [
        {
            "ioc_value": "xo98poker.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 16:56:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1960014": [
        {
            "ioc_value": "ffd88db69e131045a5dafd51d65b0ef88a59c032d4e0d79a85bf9c45566510e8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 16:39:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/ffd88db69e131045a5dafd51d65b0ef88a59c032d4e0d79a85bf9c45566510e8",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960019": [
        {
            "ioc_value": "https://fh.4toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 16:39:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b89d843f29af2eed09805e9767a1165f,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960054": [
        {
            "ioc_value": "386ecada87d6348a92eee0a6126c5a2596d14e9362f35ae01857813ffa6ae35f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 16:39:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/386ecada87d6348a92eee0a6126c5a2596d14e9362f35ae01857813ffa6ae35f",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960055": [
        {
            "ioc_value": "flingtrainer.io",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.remotecontrolclient",
            "malware_alias": "remotecontrolclient",
            "malware_printable": "RemoteControl",
            "first_seen_utc": "2026-10-10 16:39:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "HaloSword"
        }
    ],
    "1960057": [
        {
            "ioc_value": "fling-trainer.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.remotecontrolclient",
            "malware_alias": "remotecontrolclient",
            "malware_printable": "RemoteControl",
            "first_seen_utc": "2026-10-10 16:39:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "HaloSword"
        }
    ],
    "1960062": [
        {
            "ioc_value": "https://172.235.183.120",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 16:39:13",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0a9d3f5b5c13d8baec008af3c894458c,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960067": [
        {
            "ioc_value": "217.60.76.249:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-10 16:39:13",
            "last_seen_utc": "2026-10-11 06:17:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1960078": [
        {
            "ioc_value": "4fa6d321714717df4ad7b139ac074b1cac5f4853cc4bfe3f3ca328370cb577d4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 16:39:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/4fa6d321714717df4ad7b139ac074b1cac5f4853cc4bfe3f3ca328370cb577d4",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960084": [
        {
            "ioc_value": "9aace0b5aeeb83147b28efd5aebd8c51841afdd17b8f8a73a34dfc1e9d9a4fad",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 16:39:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9aace0b5aeeb83147b28efd5aebd8c51841afdd17b8f8a73a34dfc1e9d9a4fad",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1960086": [
        {
            "ioc_value": "jydyciry.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 16:35:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960085": [
        {
            "ioc_value": "foipwjgt.paketmalam.vip",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 16:31:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960081": [
        {
            "ioc_value": "181.206.118.178:5118",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-10 16:15:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960082": [
        {
            "ioc_value": "102.117.161.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 16:15:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960083": [
        {
            "ioc_value": "165.154.233.85:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 16:15:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960079": [
        {
            "ioc_value": "156.67.105.187:5698",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 16:15:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960080": [
        {
            "ioc_value": "156.67.105.187:11117",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 16:15:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960077": [
        {
            "ioc_value": "cegazy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 15:29:45",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960076": [
        {
            "ioc_value": "static-host119-73-101-199.link.net.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 15:28:12",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960075": [
        {
            "ioc_value": "hucukoly.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 15:22:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960074": [
        {
            "ioc_value": "d815901f0e6174e83fcedfd45ac47f7459bcc8ea63364185b4bfd9daa3e7d00c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960073": [
        {
            "ioc_value": "53d27245ee5e9928482f9ac7bb9b54181586eaea2b4124590a14d8e41fcf088c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960072": [
        {
            "ioc_value": "005486bf8975b090856d31bc66ee45c33880816880a9c92a31558983f2dc4561",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960071": [
        {
            "ioc_value": "75dae106cf59fbab6119d195ca38a4fffdd3128b1f26a23b088d47f4765b5435",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960070": [
        {
            "ioc_value": "d683f70abc03b4f48cce61260d8302b04b0a5551a9c6e1e8b7c4602cd9ac5811",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960069": [
        {
            "ioc_value": "fc0c410479d64f68841ffe2c4cc32e396962ad114853de913be74f576714e1bb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960068": [
        {
            "ioc_value": "2dd6e9a64ffdf45168ada584d15e6304f0bc10e9e8718f88fe4bfdd97464a4bd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 15:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960066": [
        {
            "ioc_value": "google-proxy-66-249-88-103.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 15:05:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960065": [
        {
            "ioc_value": "blog.xlab.qianxin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 15:05:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960064": [
        {
            "ioc_value": "156.67.105.187:3002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 15:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960063": [
        {
            "ioc_value": "156.67.105.187:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 15:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960061": [
        {
            "ioc_value": "4cuissch.wcimbali2016.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 14:55:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960060": [
        {
            "ioc_value": "praxis-koerperquelle.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 14:55:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960059": [
        {
            "ioc_value": "wcimbali2016.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 14:49:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1960058": [
        {
            "ioc_value": "vyloxosi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 14:43:40",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960056": [
        {
            "ioc_value": "nyp67fb4.rtpk86sport-happy.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 14:33:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960051": [
        {
            "ioc_value": "http://homecor.click:6527/documents",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-10 14:22:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960052": [
        {
            "ioc_value": "http://fgashub.shop:9932/addresses",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-10 14:22:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960053": [
        {
            "ioc_value": "http://phetsre.shop:3452/teams",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-10 14:22:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960050": [
        {
            "ioc_value": "63e726bee554a09ad7de1f8303928850b94174a8e8828c224b9d9c54dc1b2656",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 14:12:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,RustyStealer,stealer",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960049": [
        {
            "ioc_value": "165c77e0cb3fc6551babc2de99e0c5182fb86e20ac3354da7ae980b580721049",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-10 14:12:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "BRAT,exe,RAT",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960048": [
        {
            "ioc_value": "6c2446f06869a50df82165dbbc78527186cc70e8ebb50c48634de0ab9057c00a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-10 14:12:54",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,loader",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960047": [
        {
            "ioc_value": "0a5c86ee3956ef4bf3349adaef85208809b41de2f98aefd7956645e7e9ea5342",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-10 14:12:53",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,loader",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960046": [
        {
            "ioc_value": "6c977cac10245be0d1222fa444aafeed327e840a8864c7a37feb401ed51e7257",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-10 14:12:52",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960045": [
        {
            "ioc_value": "d68a9b3dcbe30b391315c02a65821c185280e00892d7e826ef12ffacafb2ee0c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-10 14:12:51",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960044": [
        {
            "ioc_value": "3d397e1e5b35f998f85b35d884b2396c2cbd523388a5e9495b4c9f9c62d57fb7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960043": [
        {
            "ioc_value": "2d3c0d6305c349e8a520a40baa6fa330478488479a8af4743e3aee5e3426c426",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960042": [
        {
            "ioc_value": "27e9b25c43479ff918ac19da04bdc0331c09de251f01c8d4cd23a84c9f4277c1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960041": [
        {
            "ioc_value": "9319b118f1abd335ebb460e1cde91bba4af3a814dfc21d27a23d1247be20fecd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960040": [
        {
            "ioc_value": "b2cc0c25c6f6e66a3d83689ec18847a9a021b92ca7d4be2cf1ebb9b5a6a49339",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960039": [
        {
            "ioc_value": "07aa27b5b6dc45d0ef4eaa38283e88fe00aa1eef6fb8ed9a4e3ee2f75ef40f19",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960038": [
        {
            "ioc_value": "e3ae43c1f29e8932d836d1c7ba9bacfc6c1977632647e4019b6a79f9eaf8ba52",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960037": [
        {
            "ioc_value": "cb939ad413e0740dfd38dcc7cdb71ef23a65ca962bd56f838c31433edcca0ac0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960036": [
        {
            "ioc_value": "d4064e80e231492a03f77e78af609213cb269bb9b8147d111336f51c2e424bc6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960035": [
        {
            "ioc_value": "5d4583cb3669b39dd95f822f45bb1fad05f01d54c2127f8fb1c2c30793795dbe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960034": [
        {
            "ioc_value": "0f00c20fc657d1bd10f8974554dff3181fe06632adf5bbb4e80b6dda2c9ed8ce",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960033": [
        {
            "ioc_value": "1ac5cdba55b0ad5e28e2f29494b47bd4a7e0f285aba40747cdb219b742ff7a8d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960032": [
        {
            "ioc_value": "f8e41136e3b1ef6daaff98f665139a528978bb375431014efd996de9ae79ec93",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 14:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960031": [
        {
            "ioc_value": "198.46.143.15:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960028": [
        {
            "ioc_value": "49.235.158.141:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960029": [
        {
            "ioc_value": "198.46.143.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960030": [
        {
            "ioc_value": "198.46.143.15:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1960027": [
        {
            "ioc_value": "45.227.253.132:58993",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 13:46:27",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960026": [
        {
            "ioc_value": "43.139.173.26:13588",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 13:46:25",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1960025": [
        {
            "ioc_value": "kyzizowa.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 13:35:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960021": [
        {
            "ioc_value": "fh.4-win.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:35:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960022": [
        {
            "ioc_value": "https://fh.4-win.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:35:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960023": [
        {
            "ioc_value": "fh.54toto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:35:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960024": [
        {
            "ioc_value": "https://fh.54toto.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:35:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960020": [
        {
            "ioc_value": "hohag85701.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 13:33:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1960015": [
        {
            "ioc_value": "fh.4toto.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:30:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960016": [
        {
            "ioc_value": "https://fh.4toto.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:30:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960017": [
        {
            "ioc_value": "fh.33pedia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:30:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960018": [
        {
            "ioc_value": "https://fh.33pedia.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 13:30:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1960013": [
        {
            "ioc_value": "https://mathang.pics/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 13:26:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "WARDENStealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1960012": [
        {
            "ioc_value": "76c3ad51a52899878a89cb49cbfc034aa810f837d893a8bff63dfa6af788f4ef",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960011": [
        {
            "ioc_value": "43157db11bdb316ec68ec0127a26f3d48aea27b2d216261f2e71240307dd927c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960010": [
        {
            "ioc_value": "e3254bbae3cee001b0998d17002b61eadafc80cbb237cdb356f7bde956782fc2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960009": [
        {
            "ioc_value": "8536ba331695b95d2d590ef3c6bf878210ad9b8d69ec4b21e44e7bd21c06ad05",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960008": [
        {
            "ioc_value": "0b4f59dcc4ba74918a9a093d9d56bb388cb48f586ebc51641383ecbf63a13211",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960007": [
        {
            "ioc_value": "15ed3dbc8d91259c9afd897e7d21009123e7d715025198c26488c8e22db76c5c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960006": [
        {
            "ioc_value": "70fb96203061d20fde5c81e512a5177efacdf9922ab01d4ea8b23cc66a610a5e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960005": [
        {
            "ioc_value": "a14cbabe19c12b812b126f32573db3ae439cf0bb4a06e2b97119509bba264a36",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960004": [
        {
            "ioc_value": "d61b49afa8bed6abcc3adea608d925777b640c6cc1c5659bf83503edcc76cb77",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960003": [
        {
            "ioc_value": "6ea903e0ed2f2077e954335f247883cd0ff5343bcdccf1bb5bfb48b40b9c224a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960002": [
        {
            "ioc_value": "9a961874a9f871e6c494280a85d710cd5d374f33efbeba58c738a82eb61f4d3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960001": [
        {
            "ioc_value": "f87a3f6bd5b29ccef54d8d32847993288c60289effe935519593aff5038eef0f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1960000": [
        {
            "ioc_value": "1445f010323973c629ba695ba6778cc92bbd3ceaaf58fd9679c321ba5303181d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959999": [
        {
            "ioc_value": "8288bdeec418d3a1cfdcb726beb42751361b8ff55a458e03a1b27d7a6c9da522",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959998": [
        {
            "ioc_value": "849d618e1c224d58cd269a06ded13047ab971ff611b254da4de414644069977b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 13:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959997": [
        {
            "ioc_value": "909c91bbe018d96d60c6b9a3b7cb29bd0a5bb733f9f72846b8edcb8a332d4b7f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.smartloader",
            "malware_alias": null,
            "malware_printable": "SmartLoader",
            "first_seen_utc": "2026-10-10 13:12:34",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,loader,SmartLoader,trojan,zip",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959996": [
        {
            "ioc_value": "49.235.158.141:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959995": [
        {
            "ioc_value": "49.235.158.141:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959994": [
        {
            "ioc_value": "160.191.52.105:88",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959993": [
        {
            "ioc_value": "160.191.52.105:82",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 13:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959853": [
        {
            "ioc_value": "https://7wm8zvijixjvah2obebyh.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959859": [
        {
            "ioc_value": "https://bm45m70ol5ave2fopggr4q.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959861": [
        {
            "ioc_value": "https://rur3c58hk2l6b4wspfaewp.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959863": [
        {
            "ioc_value": "https://2ti34h1lzcapw2f3rt8mfs.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959865": [
        {
            "ioc_value": "https://aoclbl1a7jy7swo9b0kk.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959867": [
        {
            "ioc_value": "https://4dm3itrtps8m2grskrqygf.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959873": [
        {
            "ioc_value": "https://pastebin.com/raw/V8ESQmNy",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-10 13:01:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "dead-drop,shrike,silentnet,xwormlab",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959869": [
        {
            "ioc_value": "https://3o3irtt8p0eztfqlkeso.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959871": [
        {
            "ioc_value": "https://jqpss3yzn9n3mqqkukhfs.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959872": [
        {
            "ioc_value": "http://45.141.27.27/dll/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-10 13:01:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "shrike,silentnet,xwormlab",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959875": [
        {
            "ioc_value": "https://kd06s98zp58kxcst0zywt9.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959877": [
        {
            "ioc_value": "https://njgymyclrf1pntn06lgjm.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959879": [
        {
            "ioc_value": "https://xwezrnmm0tf1vd3llbdwl.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959883": [
        {
            "ioc_value": "https://832nw30kq5rb0j4onh9tfw.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959881": [
        {
            "ioc_value": "https://7ujni7galhy2l8y6431l.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 13:01:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959959": [
        {
            "ioc_value": "76bd92cf89676f5ce2a48c5956c158382c9ee4a545261ce113f79ecde05ab5f7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 13:01:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/76bd92cf89676f5ce2a48c5956c158382c9ee4a545261ce113f79ecde05ab5f7",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959960": [
        {
            "ioc_value": "139.59.101.166:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-10 13:01:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1959992": [
        {
            "ioc_value": "brigitte7.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 12:47:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959991": [
        {
            "ioc_value": "http://105.184.158.253:37135/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 12:18:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/105.184.158.253",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959989": [
        {
            "ioc_value": "http://125.40.153.124:36333/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 12:18:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/125.40.153.124",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959990": [
        {
            "ioc_value": "http://144.48.130.194:47077/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 12:18:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/144.48.130.194",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959987": [
        {
            "ioc_value": "http://139.135.40.51:47099/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 12:18:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/139.135.40.51",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959988": [
        {
            "ioc_value": "http://117.134.206.218:41681/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 12:18:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/117.134.206.218",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959986": [
        {
            "ioc_value": "jp168amp-super.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 12:15:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959985": [
        {
            "ioc_value": "google-proxy-66-102-8-168.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 12:14:27",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959984": [
        {
            "ioc_value": "google-proxy-66-102-8-162.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 12:14:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959983": [
        {
            "ioc_value": "6c0372b4924412776f036fed3946528ab7619c7001358d3d83700f3b88a3dc2d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959982": [
        {
            "ioc_value": "dd5af3cc7fd1a458953940f8df0155f125c4814eadcf8770491634680a28a91e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959981": [
        {
            "ioc_value": "e820bd6b1c285945dbd17b68ee9e2cbe063bed78578b8993e822b94ddb4a8597",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959980": [
        {
            "ioc_value": "d28ce07924e6ba941cd2e753f665dd4ef89099032061bfd8bdb68cf2d8438ea0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959979": [
        {
            "ioc_value": "9d7bb99fcdfae5e7f2a1bb223a344e6c653f72bda831150df55759cf640e6a09",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959977": [
        {
            "ioc_value": "e17694e74233d4653626eff495d326456afa97d895c08d5b77dd8f7f2e2d4602",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959978": [
        {
            "ioc_value": "ec41a5461657d1815f375c87a3086cfd4e4f8f2714ef473deaeda63ef9120a88",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959976": [
        {
            "ioc_value": "22d48454ebefd543596ab5121573ae67d810037202a5bfae70da7798f65139e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959975": [
        {
            "ioc_value": "2ed4ad1d2d298895faa81e4cdc6420b0dd826c4ce5a5c71b7964af671a6fa55f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959974": [
        {
            "ioc_value": "6a074601e65d61b73d42d116bc9278643ac226565659022dc19a676c814c35d9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959973": [
        {
            "ioc_value": "f9415e5965082037a1730a778c4096f1af6e5f8d3c388cd867e6b999059ab392",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959972": [
        {
            "ioc_value": "682d351b7f4a7135c850f520d59acc40bef82fa3dee9f602215fcf6483175e09",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959971": [
        {
            "ioc_value": "a4108bc5a04f98e70f087bd983c60b85ea0afc53f6bad9902354830f078ee7ef",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959970": [
        {
            "ioc_value": "72a262cab5f0d6302ca19a38043488138f354329adfef13fd525bb75110c4f9a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959969": [
        {
            "ioc_value": "17adcf38a8c12ef3e980b53c44f0fb17445aea140423df3b01e3fa3c2497bd1d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959968": [
        {
            "ioc_value": "20ff1370d995557990dcd72ed53d6b8e7b74f6e401031fa86c363d820cb440ea",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959967": [
        {
            "ioc_value": "e89455525bb56b1f18857515bbf237a0a160033bdd95b8c41f1f4ee22e8936e7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959966": [
        {
            "ioc_value": "0c9b07412f1f6a3c1cead3f957b975ded1016aa0930d3be4e74e5e25ddd5226e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959965": [
        {
            "ioc_value": "fe62ef1d63982b97a87a01fb999773c6c490efbd37113d1bd494dac1e6fb095b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 12:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959963": [
        {
            "ioc_value": "160.191.52.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959964": [
        {
            "ioc_value": "160.191.52.105:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 12:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959962": [
        {
            "ioc_value": "160.191.52.105:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 12:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959961": [
        {
            "ioc_value": "156.67.105.187:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 12:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959958": [
        {
            "ioc_value": "kesahanu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 11:43:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959957": [
        {
            "ioc_value": "lulisola.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 11:36:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959956": [
        {
            "ioc_value": "tpp6b30z.kulonprogo.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 11:29:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959955": [
        {
            "ioc_value": "jabrzoza.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 11:12:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959954": [
        {
            "ioc_value": "http://118.69.157.212:9111/sshd",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.sshdoor",
            "malware_alias": null,
            "malware_printable": "SSHDoor",
            "first_seen_utc": "2026-10-10 11:09:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "elf,SSHdKit,SSHDoor",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959952": [
        {
            "ioc_value": "156.67.105.187:5011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 11:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959953": [
        {
            "ioc_value": "156.67.105.187:5601",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 11:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959950": [
        {
            "ioc_value": "157.20.182.14:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 11:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959951": [
        {
            "ioc_value": "156.67.105.187:3939",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 11:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959949": [
        {
            "ioc_value": "108.165.147.226:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 11:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959948": [
        {
            "ioc_value": "xn--instantans-j7a.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 11:02:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959947": [
        {
            "ioc_value": "v6k91pk4.truenarrator.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 10:55:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xdcf2,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959946": [
        {
            "ioc_value": "cimovo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 10:50:26",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959945": [
        {
            "ioc_value": "lonulody.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 10:46:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959944": [
        {
            "ioc_value": "http://rvweldedmesh.com:4219",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-10 10:38:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1959943": [
        {
            "ioc_value": "mdtupbnx.mawos.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 10:21:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959942": [
        {
            "ioc_value": "be9569ababf86b08921c3cf070c8bcbd31f872daca43cb9c772163e04402b0eb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-10-10 10:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,OverlordRAT",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959941": [
        {
            "ioc_value": "64.176.36.63:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 10:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959938": [
        {
            "ioc_value": "49.235.158.141:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 10:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959939": [
        {
            "ioc_value": "38.190.196.26:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 10:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959940": [
        {
            "ioc_value": "38.246.73.29:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 10:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959937": [
        {
            "ioc_value": "instantanes.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 10:02:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959936": [
        {
            "ioc_value": "gran1xea.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 10:02:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959935": [
        {
            "ioc_value": "ridiculousgwynne.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 10:02:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959934": [
        {
            "ioc_value": "dominiaband.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 09:55:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959933": [
        {
            "ioc_value": "n2dypmy2.smanbotu.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 09:53:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959932": [
        {
            "ioc_value": "waimana.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 09:52:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959931": [
        {
            "ioc_value": "smanbotu.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 09:49:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959923": [
        {
            "ioc_value": "188.245.3.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959924": [
        {
            "ioc_value": "167.233.107.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959925": [
        {
            "ioc_value": "217.60.102.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959926": [
        {
            "ioc_value": "188.245.114.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959927": [
        {
            "ioc_value": "188.245.11.133:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959928": [
        {
            "ioc_value": "212.147.244.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959929": [
        {
            "ioc_value": "77.42.10.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959930": [
        {
            "ioc_value": "94.237.14.115:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:46:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959921": [
        {
            "ioc_value": "xt.33pedia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:43",
            "last_seen_utc": "2026-10-10 09:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959922": [
        {
            "ioc_value": "xt.4toto.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:43",
            "last_seen_utc": "2026-10-10 09:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959920": [
        {
            "ioc_value": "94.158.187.146:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:45:41",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959919": [
        {
            "ioc_value": "68.166.230.226:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:45:26",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959911": [
        {
            "ioc_value": "https://188.245.3.116/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959912": [
        {
            "ioc_value": "https://167.233.107.104/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959913": [
        {
            "ioc_value": "https://217.60.102.185/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959914": [
        {
            "ioc_value": "https://188.245.114.219/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959915": [
        {
            "ioc_value": "https://188.245.11.133/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959916": [
        {
            "ioc_value": "https://212.147.244.162/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959917": [
        {
            "ioc_value": "https://77.42.10.33/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959918": [
        {
            "ioc_value": "https://94.237.14.115/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 09:45:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1959910": [
        {
            "ioc_value": "5.163.189.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-10 09:45:17",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959908": [
        {
            "ioc_value": "46.246.6.8:9878",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-10 09:45:15",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959909": [
        {
            "ioc_value": "46.246.84.14:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 09:45:15",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959907": [
        {
            "ioc_value": "46.101.18.134:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 09:45:13",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959906": [
        {
            "ioc_value": "38.76.199.254:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 09:44:59",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959905": [
        {
            "ioc_value": "37.221.66.206:43399",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-10 09:44:56",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959904": [
        {
            "ioc_value": "207.180.6.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:44:20",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959903": [
        {
            "ioc_value": "2.26.99.48:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-10-10 09:44:15",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959901": [
        {
            "ioc_value": "192.154.225.35:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 09:44:05",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959902": [
        {
            "ioc_value": "192.154.225.35:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 09:44:05",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959900": [
        {
            "ioc_value": "192.120.42.219:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:44:04",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959899": [
        {
            "ioc_value": "173.214.167.250:7730",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-10 09:43:51",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959897": [
        {
            "ioc_value": "156.252.173.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:43:39",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959898": [
        {
            "ioc_value": "156.252.79.222:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:43:39",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959895": [
        {
            "ioc_value": "156.236.0.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959896": [
        {
            "ioc_value": "156.236.1.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-10 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959894": [
        {
            "ioc_value": "149.104.71.157:61489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 09:43:32",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959893": [
        {
            "ioc_value": "espace-zigzag.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 09:36:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959892": [
        {
            "ioc_value": "https://clward.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 09:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/clward.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959891": [
        {
            "ioc_value": "198.46.143.15:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 09:30:07",
            "last_seen_utc": "2026-10-10 15:05:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959890": [
        {
            "ioc_value": "atelierdezigzag.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 09:26:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959889": [
        {
            "ioc_value": "e3c4eab8fdd4782669a2101e8ead8fabf8f24f65da4099e31be43b4fc5c32658",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 09:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959888": [
        {
            "ioc_value": "c680d68751452168707fb5235bacbcfe766bb34ad2b7d14f04c4746a14c1735a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 09:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959887": [
        {
            "ioc_value": "49.235.158.141:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 09:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959886": [
        {
            "ioc_value": "49.235.158.141:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 09:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959885": [
        {
            "ioc_value": "momytojy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 08:58:01",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959884": [
        {
            "ioc_value": "hopypo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 08:52:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959882": [
        {
            "ioc_value": "832nw30kq5rb0j4onh9tfw.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:32:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959880": [
        {
            "ioc_value": "7ujni7galhy2l8y6431l.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:32:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959878": [
        {
            "ioc_value": "xwezrnmm0tf1vd3llbdwl.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:31:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959876": [
        {
            "ioc_value": "njgymyclrf1pntn06lgjm.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:30:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959874": [
        {
            "ioc_value": "kd06s98zp58kxcst0zywt9.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:29:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959870": [
        {
            "ioc_value": "jqpss3yzn9n3mqqkukhfs.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:28:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959868": [
        {
            "ioc_value": "3o3irtt8p0eztfqlkeso.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:27:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959866": [
        {
            "ioc_value": "4dm3itrtps8m2grskrqygf.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:26:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959864": [
        {
            "ioc_value": "aoclbl1a7jy7swo9b0kk.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:24:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959862": [
        {
            "ioc_value": "2ti34h1lzcapw2f3rt8mfs.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:23:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959860": [
        {
            "ioc_value": "rur3c58hk2l6b4wspfaewp.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:22:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959858": [
        {
            "ioc_value": "bm45m70ol5ave2fopggr4q.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:15:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959857": [
        {
            "ioc_value": "6d9bb3f2375a8f2e54ef154e7b6fd5e3d7763eb4cbd07fd742a6eafb2ccc0fea",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 08:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959856": [
        {
            "ioc_value": "3363028cb9cebe5beaf8813beb1cb5f0f8879eebece9c370a6321c162f44d7f7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 08:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959855": [
        {
            "ioc_value": "http://154.91.180.246:18080/?h=154.91.180.246&p=18080&t=ws&a=l64&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 08:08:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959854": [
        {
            "ioc_value": "50a336isqu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 08:07:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959852": [
        {
            "ioc_value": "7wm8zvijixjvah2obebyh.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 08:06:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959851": [
        {
            "ioc_value": "49.235.158.141:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 08:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959849": [
        {
            "ioc_value": "156.67.105.187:7383",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959850": [
        {
            "ioc_value": "49.235.158.141:888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959848": [
        {
            "ioc_value": "virazofurniture.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 08:02:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959847": [
        {
            "ioc_value": "91.193.18.245:61010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:55:19",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/91.193.18.245",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959846": [
        {
            "ioc_value": "49.51.199.234:29871",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:55:11",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/49.51.199.234",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959845": [
        {
            "ioc_value": "45.94.31.42:31336",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:55:07",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/45.94.31.42",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959844": [
        {
            "ioc_value": "45.207.219.181:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:55:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/45.207.219.181",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959843": [
        {
            "ioc_value": "45.142.31.82:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:55:00",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/45.142.31.82",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959842": [
        {
            "ioc_value": "45.13.237.45:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:54:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/45.13.237.45",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959841": [
        {
            "ioc_value": "192.200.102.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:54:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/192.200.102.198",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959840": [
        {
            "ioc_value": "182.255.46.81:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:54:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/182.255.46.81",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959839": [
        {
            "ioc_value": "168.138.207.32:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:54:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/168.138.207.32",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959838": [
        {
            "ioc_value": "154.93.103.232:60317",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:54:41",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/154.93.103.232",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959837": [
        {
            "ioc_value": "107.172.35.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-10 07:54:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/107.172.35.207",
            "tags": "modat,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959836": [
        {
            "ioc_value": "83.229.121.34:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 07:54:29",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://magnify.modat.io/hosts/83.229.121.34",
            "tags": "modat,supershell",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1959833": [
        {
            "ioc_value": "7a58f0560aebb4c31ad6ead45c15d336a5e00598923f43e25a1a555e37f1b3a2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 07:35:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/7a58f0560aebb4c31ad6ead45c15d336a5e00598923f43e25a1a555e37f1b3a2",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959835": [
        {
            "ioc_value": "morib.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 07:34:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959834": [
        {
            "ioc_value": "clward.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 07:32:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959832": [
        {
            "ioc_value": "http://straely.biz:8531/imports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-10 07:15:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1959831": [
        {
            "ioc_value": "bdc441c351f890995e449883473762caabb7d3dd772ed863d1a59ec1a2403387",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959830": [
        {
            "ioc_value": "88e2be8a45582e5b4922a131960eddc9aa7a767f194fa51bb3c0e4d11f8b8ccc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959829": [
        {
            "ioc_value": "9f84ae5cf59379509f11668525b107808adcc8b6f819fc3d00c8a4980a09b307",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959828": [
        {
            "ioc_value": "4587c320988021e05d994f96901c6e91d47f9ab3c965a64b22dd14437b4bc23c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959827": [
        {
            "ioc_value": "037a8526c5b62cdae7552113e3e580dd47a90ca1f5c0fcca0aac8b7b07c1f835",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959826": [
        {
            "ioc_value": "2e892431668abc0edfa63f56ec3558f8ab8db5ad57c2b27ccc2fe0a3273744f0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959825": [
        {
            "ioc_value": "1c8f9a57fe84029071cf4626ee34e3bd6e20e8c10dad4d0b45ae546ac5641485",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959824": [
        {
            "ioc_value": "fbe985dafb80cd950c56f5e12a9e73494dab2952c096855873c1f4684fd8efce",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959823": [
        {
            "ioc_value": "451ecec559498f05623d59743f1a56cb121b6b5cbb2ab79dc6290fdf4c0669cf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959822": [
        {
            "ioc_value": "f5810732a2cd17daf05855b29db87ee03b73f41d954a4c7f4244d8c4e766a119",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959821": [
        {
            "ioc_value": "e2534f2b25928b9b258c0102184d7754fd8fc2341a0431f781b15a390bba147e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959820": [
        {
            "ioc_value": "962074ad9a128c3fad2a02fc9065dfe48b731b94c0e05f34e2e6a5ecffd2e7c9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959819": [
        {
            "ioc_value": "b80c4833fff96c8d87fc07b0e0e3f89ae007ae79e8bd09b482ff484fbc0f4b58",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959818": [
        {
            "ioc_value": "825ab16aae47860282332000990d5566edcd04e8e63284723a53838d71b6a55d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959817": [
        {
            "ioc_value": "a7434d5503e489ae82e9735a1ba550154b281669b88dfdfe333db868c641cdf0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959816": [
        {
            "ioc_value": "774a4bd75698dfa1ad64c73afd37e1f92cca395aea12c5e931e21f61d6cc8c67",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959815": [
        {
            "ioc_value": "603ea7cb6035de6c10c2d1cac0f1ab5355a96e60a7235eaecafc832ec9a5e29d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959814": [
        {
            "ioc_value": "99133b9c24de23c8843ceefdb58a8888a2713360a9f4d2f6d9ced0d6924174a7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959813": [
        {
            "ioc_value": "8eea5c63a95c5ba54e08af8162ed6b09dbb35493050f27396fd924fd3f8c3798",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 07:12:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959807": [
        {
            "ioc_value": "e6040ffde33fdbfd13583614e35b60038e5a461d31a1bf2d22dfc3506333391e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 07:09:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/e6040ffde33fdbfd13583614e35b60038e5a461d31a1bf2d22dfc3506333391e",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959811": [
        {
            "ioc_value": "156.67.105.187:3001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 07:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959812": [
        {
            "ioc_value": "156.67.105.187:3023",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 07:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959809": [
        {
            "ioc_value": "93.185.165.104:18963",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959810": [
        {
            "ioc_value": "156.67.105.187:1341",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959808": [
        {
            "ioc_value": "39.96.65.0:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 07:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959806": [
        {
            "ioc_value": "risepobo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 07:02:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959805": [
        {
            "ioc_value": "62r6hrqaoj.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 07:00:16",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959804": [
        {
            "ioc_value": "ziwuvexy.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 06:51:45",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959803": [
        {
            "ioc_value": "146-241-111-165.dyn.eolo.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 06:28:05",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959797": [
        {
            "ioc_value": "195.20.19.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:14",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959798": [
        {
            "ioc_value": "195.20.19.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:14",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959799": [
        {
            "ioc_value": "195.20.19.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:14",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959800": [
        {
            "ioc_value": "43.156.29.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:14",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959801": [
        {
            "ioc_value": "43.173.6.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:14",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959802": [
        {
            "ioc_value": "8.213.238.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:14",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959794": [
        {
            "ioc_value": "124.156.214.122:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:13",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959795": [
        {
            "ioc_value": "195.20.19.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:13",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959796": [
        {
            "ioc_value": "195.20.19.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-10 06:21:13",
            "last_seen_utc": "2026-10-11 06:24:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959793": [
        {
            "ioc_value": "http://115.53.201.33:44073/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 06:18:39",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/115.53.201.33",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959791": [
        {
            "ioc_value": "http://36.49.52.140:36933/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 06:18:38",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/36.49.52.140",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959792": [
        {
            "ioc_value": "31.56.19.111:15987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-10 06:18:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959790": [
        {
            "ioc_value": "523db43eac031043521e0a8a7d0c30eb13d5bd66bb3096cec9be38a8895ea13e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959789": [
        {
            "ioc_value": "abb018512ef40ba5e9aca1ca6fccc4572de60eb23fc79ba798cdc549f63ac27b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959788": [
        {
            "ioc_value": "38474707724c5fdc9a4cba7a60797ce14e0cdaecd6f11b49acb12dddf8d3753c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959787": [
        {
            "ioc_value": "73ab4a2ffece356b303b7248f78c62fddf80300cdeb7e219cd178e0f09fbb920",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959786": [
        {
            "ioc_value": "5a0da401ff83bb724aadb46aa91e877df6dc288dc82af68641a3acbaa1434c96",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959785": [
        {
            "ioc_value": "1a09814dcd1a18ad86c3789658bcb515dc241e3bcee3444be7dd48cf8a846f74",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959784": [
        {
            "ioc_value": "b3d283ad82c2328cb09a8f3dee94c3c4813cad98f7680554dec8122d1c32ea63",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959783": [
        {
            "ioc_value": "6dfba6f8258418683002d77be91fba1abe8527baab12a1013e161bc394f959f8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:12:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959782": [
        {
            "ioc_value": "j0p0cibb.lunza.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 06:07:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959779": [
        {
            "ioc_value": "39.96.65.0:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 06:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959780": [
        {
            "ioc_value": "39.96.65.0:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 06:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959781": [
        {
            "ioc_value": "39.96.65.0:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 06:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959777": [
        {
            "ioc_value": "2.50.131.185:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 06:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959778": [
        {
            "ioc_value": "39.96.65.0:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 06:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959146": [
        {
            "ioc_value": "46.246.12.24:5987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-10 06:02:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,NMUOnAPUAPU,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1959147": [
        {
            "ioc_value": "0dc6c8916d54de3bf5df5bba7c573cc1efd71d934716649cf93732babd09d24e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:12",
            "last_seen_utc": "2026-10-09 20:40:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "loader,runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959148": [
        {
            "ioc_value": "a377cdd07136d9f6bd6e9cb23a5e7ab7d78dd7fccaa867d741286dc238135548",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:12",
            "last_seen_utc": "2026-10-09 20:40:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "loader,runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959149": [
        {
            "ioc_value": "b4b600bd109160520277af06caca40b121fa588ea0924f6c9f342b3e4ed0a2f5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "loader,runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959150": [
        {
            "ioc_value": "49b5021a4be924b200b7049a77e78081d986362f571c0c30ec9eebd95bd14483",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "loader,runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959151": [
        {
            "ioc_value": "ad0c08a40934df311ba55d4cf17747cd748b6ac565d156e99c0f785b0388d19c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "loader,runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959152": [
        {
            "ioc_value": "58d14743bfd7917e84c0dc423484c78eee18efe04c42f368933f5f87468b1acf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "loader,runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959154": [
        {
            "ioc_value": "https://dupe.dupe543.workers.dev/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-10 06:02:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "jar,java,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959437": [
        {
            "ioc_value": "https://hp.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 06:02:09",
            "last_seen_utc": "2026-10-10 18:53:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b98dd86b169ec45dd28e99dcad12402a,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1959441": [
        {
            "ioc_value": "https://www.osmb.net/OSMB.jar",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 06:02:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959442": [
        {
            "ioc_value": "www.osmb.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 06:02:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "coinminer,runelure",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959443": [
        {
            "ioc_value": "osbot.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 06:02:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "coinminer,runelure",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959489": [
        {
            "ioc_value": "999.34c9f78b4ef541baac4a6e84d4f832a7.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:02:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96/behavior",
            "tags": "botnet",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1959490": [
        {
            "ioc_value": "b65d1f2fb47de8bd278b685b7b787fee69b65232b678ac8721ca41896c7bf544",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:02:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b65d1f2fb47de8bd278b685b7b787fee69b65232b678ac8721ca41896c7bf544",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959493": [
        {
            "ioc_value": "5.83.134.80:24331",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:02:04",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1959495": [
        {
            "ioc_value": "213.232.114.14:21",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-10 06:02:04",
            "last_seen_utc": "2026-10-09 22:00:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1959494": [
        {
            "ioc_value": "13.140.176.180:24331",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:02:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1959496": [
        {
            "ioc_value": "213.232.114.14:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-10 06:02:02",
            "last_seen_utc": "2026-10-09 22:15:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1959497": [
        {
            "ioc_value": "77.90.57.20:8080",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:02:02",
            "last_seen_utc": "2026-10-09 21:54:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1959499": [
        {
            "ioc_value": "http://5kiwqdzvhip5yjx5u6ms2hsv3yozpslxocjhyf4cyimrg33fcb7devid.onion/api/hlam/files/4000",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-10 06:02:01",
            "last_seen_utc": "2026-10-10 07:51:07",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f43d830bfd15726e870b2459f269db3bfc7db601bf86cc0a91c7cb2732331eaa/",
            "tags": "jar,java,minecraft,tor",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1959513": [
        {
            "ioc_value": "prod-static.nascarnash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-10-10 06:02:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@monitorsg/117413253207385243",
            "tags": "SocGholish",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1959514": [
        {
            "ioc_value": "143.20.154.42:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:01:59",
            "last_seen_utc": "2026-10-09 22:15:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "honeypot",
            "anonymous": 0,
            "reporter": "vlasovmichael"
        }
    ],
    "1959515": [
        {
            "ioc_value": "http://138.226.247.154/session/8ea0e4ef65dd189c",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:01:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BSC,EtherHiding,FakeInterview,NodeJS,Tron",
            "anonymous": 0,
            "reporter": "molion"
        }
    ],
    "1959519": [
        {
            "ioc_value": "846cedfc657e8c62c59904fe0f4849a2de49ddd8b269b062863ba56322ba4b10",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/846cedfc657e8c62c59904fe0f4849a2de49ddd8b269b062863ba56322ba4b10",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959522": [
        {
            "ioc_value": "https://sa.microdenmem.workers.dev/m/license-20260921055229-9722",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "jar.microstealer",
            "malware_alias": null,
            "malware_printable": "MicroStealer",
            "first_seen_utc": "2026-10-10 06:01:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Discord,java,MicroStealer,RAT,stealer",
            "anonymous": 0,
            "reporter": "chrono"
        }
    ],
    "1959523": [
        {
            "ioc_value": "https://discord.com/api/webhooks/1556790836333912135/ASzKY2G0UUF1TA6UTTu-Vj5DfcTB3f3Ya18oYcD2XkyglZcaXh910WENDoTJT-q03oIM",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "jar.microstealer",
            "malware_alias": null,
            "malware_printable": "MicroStealer",
            "first_seen_utc": "2026-10-10 06:01:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Discord,java,MicroStealer,RAT,stealer",
            "anonymous": 0,
            "reporter": "chrono"
        }
    ],
    "1959524": [
        {
            "ioc_value": "9e99b89d9c17fa8068cd214854e053f1f29e87f8e1a8f0dff4f3c52f60ea3b10",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.microstealer",
            "malware_alias": null,
            "malware_printable": "MicroStealer",
            "first_seen_utc": "2026-10-10 06:01:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Discord,java,MicroStealer,RAT,stealer",
            "anonymous": 0,
            "reporter": "chrono"
        }
    ],
    "1959562": [
        {
            "ioc_value": "27015e5d3fb643438d1a0d3387b6e254085e9d3218023a3064612836d1226ed3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/27015e5d3fb643438d1a0d3387b6e254085e9d3218023a3064612836d1226ed3",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959640": [
        {
            "ioc_value": "https://brows-check.codes",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:01:56",
            "last_seen_utc": "2026-10-10 08:32:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959641": [
        {
            "ioc_value": "c54847abf0244aa9dbf6e84e6f38cafae01086a8f2f2c74a8c4ad12bdfd6c54f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c54847abf0244aa9dbf6e84e6f38cafae01086a8f2f2c74a8c4ad12bdfd6c54f/",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959644": [
        {
            "ioc_value": "https://xt.33pedia.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 06:01:55",
            "last_seen_utc": "2026-10-10 09:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/4dbc2a3dcbd0a5a711f45789a4367cd959fc0dcc37ddc1d6e335cb98925aa688/behavior",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1959645": [
        {
            "ioc_value": "https://xt.4toto.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 06:01:54",
            "last_seen_utc": "2026-10-10 09:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b6ea43e7f0371f5278f7d56dbdea7da203fe51976f5ea3751aff0598d44d8921/behavior",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1959647": [
        {
            "ioc_value": "33pedia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 06:01:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/4dbc2a3dcbd0a5a711f45789a4367cd959fc0dcc37ddc1d6e335cb98925aa688/behavior",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1959648": [
        {
            "ioc_value": "9bf7j6bzrzzg.ifuckurmomjaffacakes.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:01:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "bytenode,Discord,Electron,fake-game,HADES,RAT,stealer",
            "anonymous": 0,
            "reporter": "secuJay"
        }
    ],
    "1959649": [
        {
            "ioc_value": "ifuckurmomjaffacakes.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:01:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "bytenode,Discord,Electron,fake-game,HADES,RAT,stealer",
            "anonymous": 0,
            "reporter": "secuJay"
        }
    ],
    "1959650": [
        {
            "ioc_value": "4toto.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 06:01:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b6ea43e7f0371f5278f7d56dbdea7da203fe51976f5ea3751aff0598d44d8921/behavior",
            "tags": "c2,vidar",
            "anonymous": 0,
            "reporter": "Kejult"
        }
    ],
    "1959670": [
        {
            "ioc_value": "168.245.203.127:3790",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.meterpreter",
            "malware_alias": null,
            "malware_printable": "Meterpreter",
            "first_seen_utc": "2026-10-10 06:01:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "58580,c2,censys,metasploit",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1959672": [
        {
            "ioc_value": "https://hp.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-10 06:01:50",
            "last_seen_utc": "2026-10-11 07:30:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,de4cf22e4d9de058fc3cfd2267ee4cc9,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1959712": [
        {
            "ioc_value": "85.137.53.167:3169",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:01:50",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9e3aa12ebf0d32b7e315de5e0fc742c6f504e35ddedf2ba4205b9bd56ad52224/",
            "tags": "cowrie,elf,honeypot,mips,Mirai,telnet",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1959711": [
        {
            "ioc_value": "3c276484058953ab0c4d6bffbe7be81f055c61da6291bd13fc5b0b25133c7ba2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/3c276484058953ab0c4d6bffbe7be81f055c61da6291bd13fc5b0b25133c7ba2",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959715": [
        {
            "ioc_value": "159.65.67.52:44992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:01:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/55d19b5c675819d5d2492e10bd44028d3e02426c7fa486c4515b804943e8d54e/",
            "tags": "cowrie,dns-xor,elf,honeypot,Mirai,telnet,x86",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1959724": [
        {
            "ioc_value": "206.189.164.5:44559",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 06:01:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://threatfox.abuse.ch/ioc/1959715/",
            "tags": "cowrie,dns-xor,elf,honeypot,Mirai,telnet,x86",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1959738": [
        {
            "ioc_value": "5c57172cf372f16845fa1f232260c34386e8acb3dada5458b7b809873595b0ae",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/5c57172cf372f16845fa1f232260c34386e8acb3dada5458b7b809873595b0ae",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959740": [
        {
            "ioc_value": "178.16.53.68:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-10 06:01:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1959750": [
        {
            "ioc_value": "27871baf8b0b80105adaf134a90c39d968273bc7bb5f9ec8049d661e09332083",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/27871baf8b0b80105adaf134a90c39d968273bc7bb5f9ec8049d661e09332083",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959764": [
        {
            "ioc_value": "https://check-codbrowse.beer",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:01:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959766": [
        {
            "ioc_value": "https://brows-check-ids.codes",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 06:01:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,ErrTraffic,EtherHiding,Polygon",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1959767": [
        {
            "ioc_value": "280e8ba4350911ec2908945abc8012332cd86d6bbb769bbe589f22de3aa639b8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-10 06:01:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/280e8ba4350911ec2908945abc8012332cd86d6bbb769bbe589f22de3aa639b8",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1959776": [
        {
            "ioc_value": "91.193.43.38:4748",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 06:00:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "QuasarRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959775": [
        {
            "ioc_value": "94.154.43.12:23",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 05:59:12",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/61df29da73da82fc5c767946804189d1d94c105dd54b01ec786202e9b451bbc4/",
            "tags": "Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959774": [
        {
            "ioc_value": "7ubpxz82hg.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 05:56:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959772": [
        {
            "ioc_value": "penislandrocket.gov.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 05:49:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959770": [
        {
            "ioc_value": "32323421342.gov.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 05:49:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959768": [
        {
            "ioc_value": "3232342342.gov.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 05:48:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959765": [
        {
            "ioc_value": "brows-check-ids.codes",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 05:40:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959763": [
        {
            "ioc_value": "check-codbrowse.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 05:24:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959762": [
        {
            "ioc_value": "misle.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 05:14:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959761": [
        {
            "ioc_value": "4969607e53fb15d4681f663d521ea0e70f565ed83ffd1042e9c2f2d77a9f5112",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 05:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959760": [
        {
            "ioc_value": "0203fcb09d396bed27adaf248ee33aca03c9e048bfd98555e966b30b122d426a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 05:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959759": [
        {
            "ioc_value": "90feb8a42116a8687589bcf05e1eb6ad645f55a777931b0436ea58c9e58a97cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 05:12:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959758": [
        {
            "ioc_value": "487aa2dd15f26be8158d5440ea9496c3aad1953798813c26aac735651d9c6aa0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 05:12:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959756": [
        {
            "ioc_value": "222.231.27.161:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-10 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959757": [
        {
            "ioc_value": "39.96.65.0:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-10 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959755": [
        {
            "ioc_value": "rtplive-miliarbet.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 04:48:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959754": [
        {
            "ioc_value": "kflm3k81.rtplive-miliarbet.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 04:48:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959753": [
        {
            "ioc_value": "zodysate.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 04:29:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959752": [
        {
            "ioc_value": "86.163.111.183:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-10-10 04:25:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "QuasarRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959751": [
        {
            "ioc_value": "40faint.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 04:19:28",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959749": [
        {
            "ioc_value": "0cb95865025d78cfd81b430b58b72871ea74e8e5831d7b32727da0969565d303",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.smartloader",
            "malware_alias": null,
            "malware_printable": "SmartLoader",
            "first_seen_utc": "2026-10-10 04:12:35",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,loader,SmartLoader,trojan,zip",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959748": [
        {
            "ioc_value": "64baec6013414eacd268a91e105e652b8e125e231821100c619d0060a79c37da",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 04:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959747": [
        {
            "ioc_value": "3fa7e27442f328fc3f5f905bc5bf1444626cbf6dc02afd289bbca783200f43d8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 04:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959746": [
        {
            "ioc_value": "aba60b306f7287a105aebfefe45c151b8e77ceaa0b528ab5d5553094baf4cc07",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 04:12:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959745": [
        {
            "ioc_value": "b5a0f571387cc53c1f817b322e543ab8ef2078bd0e61e1a2fa4fcabe9f43a7fb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 04:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959744": [
        {
            "ioc_value": "347ff4da8029c5aede97394b6cb3a59b267e3b6916d4d4e6561e5a248ea56f44",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 04:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959743": [
        {
            "ioc_value": "762a6ad0a16496eb59595002af5fef4e75e53466ff983808ce40ea296701541a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 04:12:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959742": [
        {
            "ioc_value": "http://2.26.225.232/main.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.xmrig",
            "malware_alias": null,
            "malware_printable": "xmrig",
            "first_seen_utc": "2026-10-10 04:08:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "coinminer,exe,xmrig",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959741": [
        {
            "ioc_value": "38.55.252.139:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 04:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "viper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959739": [
        {
            "ioc_value": "samehoo229.fun",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 03:49:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959737": [
        {
            "ioc_value": "https://zonainfo.biz.id/?i=1",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 03:30:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/zonainfo.biz.id",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959736": [
        {
            "ioc_value": "zitysade.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 03:21:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959735": [
        {
            "ioc_value": "31.56.19.111:23789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-10 03:14:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959734": [
        {
            "ioc_value": "8d1aaf7b5343e6d13828f68e65e165c394076751b83d01b3642758820c0641b5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 03:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959733": [
        {
            "ioc_value": "38d44f640904030bcf70790366c5e11e9153cb25a4af6b2ec2b68deb6a2f0630",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 03:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959732": [
        {
            "ioc_value": "f9e49785ed4afb303cc6540bbc20b8d09889f568eb8b54e9a6c03c8985227417",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 03:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959731": [
        {
            "ioc_value": "c51c6272590c97dc57835e9ee27c3f96060dba964af8f6eab523de807706e2c6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 03:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959730": [
        {
            "ioc_value": "http://148.66.17.122:60003/?h=148.66.17.122&p=60003&t=ws&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 03:08:14",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959729": [
        {
            "ioc_value": "https://qelvhash.com/dl/qelvminer-1.1.0-windows-x86_64.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.mirai",
            "malware_alias": null,
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 03:08:02",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959728": [
        {
            "ioc_value": "http://148.66.17.125:60003/?h=148.66.17.125&p=60003&t=ws&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 03:07:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959727": [
        {
            "ioc_value": "http://102.129.165.178:8443/?h=102.129.165.178&p=8443&t=ws&a=w64&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 03:07:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959726": [
        {
            "ioc_value": "http://102.129.165.178:8443/?h=102.129.165.178&p=8443&t=ws&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 03:06:20",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959725": [
        {
            "ioc_value": "104.234.26.225:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 03:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959723": [
        {
            "ioc_value": "34982876ca4776ebaca652e152141a226b6b6d03e0be32f1ba046629bde6d781",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959722": [
        {
            "ioc_value": "dc5dff4a23be303fe1d8d37fde70744f8be3237dd7dd41c4a1c96a523f032b1e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959721": [
        {
            "ioc_value": "1c39d5b7fd20f7d696ca4697abc07a3e08e73496975df0e37a5da0c956e8316c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959720": [
        {
            "ioc_value": "b0b2af0d3f774245eb60ec64e200cd2f178f9efd18c945a64010534e9f75241a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959719": [
        {
            "ioc_value": "5ff5b076b57b5e3ab41db66cba6cf846b9af4bf88de05817ef2c18e970843ebe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959718": [
        {
            "ioc_value": "e10a5890f6e7515961b3cb1184f8315b886174d07d8d7e58386bad3ccb07f822",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959717": [
        {
            "ioc_value": "6dda01bc822dcff5a081176b611e85c3324bfe642f224ace9942b8cf7d1ce0a0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 02:12:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959716": [
        {
            "ioc_value": "8rlmyiu3.b00kself.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 02:10:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959714": [
        {
            "ioc_value": "qolyvohu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 01:55:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959713": [
        {
            "ioc_value": "nuzufico.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 01:50:14",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959710": [
        {
            "ioc_value": "https://venom189.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/venom189.org",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959709": [
        {
            "ioc_value": "0405d097883e17cac15578d2f7e3fb7e0ae96c978249103d78d87c048d50f263",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:13:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959707": [
        {
            "ioc_value": "609b5bf37bc6544d7b74a77339144e089aeff5bdc578ce13fd8aa015c59a8343",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:13:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959708": [
        {
            "ioc_value": "474477c0690528ae5c49d5ffc0f255eaf61d05e8e7b394720121afc3057632cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:13:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959706": [
        {
            "ioc_value": "9845c245686ccf24c72044fd6d1f6d0be7a4ee528efc0194b39741c51f330bce",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.mirai",
            "malware_alias": null,
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:13:01",
            "last_seen_utc": "2026-10-10 21:08:46",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959705": [
        {
            "ioc_value": "385c518f5251712671b029d3e862a4d4ce25dea3c4d578c6512f1d4d911cf14d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 01:12:59",
            "last_seen_utc": "2026-10-10 21:08:54",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Coinminer,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959703": [
        {
            "ioc_value": "9d294361a6c61ce1c1617f80b9bad73f82c949c2e455d3289138094652e3afd7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959704": [
        {
            "ioc_value": "086b643e503d08276a147e70df02cdb635cdf8fb8624edb168f9b7ee75f3022c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959702": [
        {
            "ioc_value": "8d4fb5f3f54d19f3c5b47bdfd928e58fabe37b40d8d105c458eabef910112ebb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959701": [
        {
            "ioc_value": "2f24dd111889c1878b8a4fb688754568ad2d138536480a1dd3d57baa2bb38257",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959700": [
        {
            "ioc_value": "9751fd974c94c2fc596ad4cd40b005fb15b7812bf236e4fee14368b5b2d1c9c1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959699": [
        {
            "ioc_value": "b8d04987bf3df3be130d397a7bef47d3396680a424505ffae489841588c95f52",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959698": [
        {
            "ioc_value": "bb48f3d7057d2675a7cc6a589e5fb2402e30ec991971ad9b26003fad4758fa95",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959697": [
        {
            "ioc_value": "79f387555290301b619d838a9c260854e91fd7f919850c1a44b9d690c75b339d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959696": [
        {
            "ioc_value": "34e7bb86115ed921f1f022db56226614c6aa7aa23d55feb3e5af60eb616d3cff",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 01:12:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959695": [
        {
            "ioc_value": "8ca3402d2d33cff125b3d7a9932208f4b1e9f0cf33c9bbbb8eed24fb6c650559",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:50",
            "last_seen_utc": "2026-10-10 21:08:40",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959694": [
        {
            "ioc_value": "528458c9d7ac88959d2d83aecd0544bf75727d34795deaf658ff3b82000a9e44",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-10 01:12:49",
            "last_seen_utc": "2026-10-10 21:09:05",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "Coinminer,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959693": [
        {
            "ioc_value": "c47f53b3c8c6768ad2852aed0e8f3ecf4a113d663933738a7f6890e57cb431c2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:48",
            "last_seen_utc": "2026-10-10 21:09:00",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959692": [
        {
            "ioc_value": "ee8516779bc3b64f143d7513dd30e5f722d11e86788fd7dfc13e5dc43bd35d3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:47",
            "last_seen_utc": "2026-10-10 21:08:57",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959691": [
        {
            "ioc_value": "9aedde256523c41a2fcd7e7c5ab6d4696bc02a998144b8cdea551fa57e6953f6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:46",
            "last_seen_utc": "2026-10-10 21:08:56",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959690": [
        {
            "ioc_value": "1740beac423979afea7496e51ea5f2e28b0f920ad92bb2ed12a81bd801ac5e0c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:45",
            "last_seen_utc": "2026-10-10 21:08:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959689": [
        {
            "ioc_value": "12a43fee749a3596766958bfe9111e4874de2d90c4d7a5df2ebe5606694e0984",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:44",
            "last_seen_utc": "2026-10-10 21:08:39",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959688": [
        {
            "ioc_value": "35b15d6c1af38f79556e8b3e99486e5d8d34039e037675eca021c3503ec0a3b1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:43",
            "last_seen_utc": "2026-10-10 21:08:37",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959687": [
        {
            "ioc_value": "ca4882f7dd6dd9ee717d98912d9d7098d55bc1933591c38f4e33f94b2c69ca52",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:42",
            "last_seen_utc": "2026-10-10 21:09:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959686": [
        {
            "ioc_value": "ee5e9d5f0c7c6916eabd0d6bb9db573fb0c2808924c2e41dd9f3224d789981d7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:41",
            "last_seen_utc": "2026-10-10 21:08:48",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959685": [
        {
            "ioc_value": "7cc5e09cdbd34044e1a4229a55abab7423460614e42c3b8701e65f89d4f8ee42",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:40",
            "last_seen_utc": "2026-10-10 21:08:43",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959684": [
        {
            "ioc_value": "ffda934a9acd3bdf14128a14812049f0558d75b63677f346c16204427a483540",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.babadeda",
            "malware_alias": null,
            "malware_printable": "Babadeda",
            "first_seen_utc": "2026-10-10 01:12:39",
            "last_seen_utc": "2026-10-10 21:08:36",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "Babadeda,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959683": [
        {
            "ioc_value": "8bce3301fd794b9d2fbe22526dfc5aa1e2c12ce59aa1556961aafa00eb92733a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:38",
            "last_seen_utc": "2026-10-10 21:08:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959682": [
        {
            "ioc_value": "011fd979619d97af8e1891c263fed4993e7093ab6a6e290b48ecee3d166d74d0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:37",
            "last_seen_utc": "2026-10-10 21:08:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959681": [
        {
            "ioc_value": "422c7f97e2b5eed63bf06c7f51aa1f6b8b8a859f7c856b8a0404051894b035ac",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:36",
            "last_seen_utc": "2026-10-10 21:08:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959680": [
        {
            "ioc_value": "322f75a96b8489ce66f833cc61785e25e595a2cac3bede7f7542c96cd6c45441",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:35",
            "last_seen_utc": "2026-10-10 21:08:55",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959679": [
        {
            "ioc_value": "f7102105b79d9fa37298a981ff043a466c397da473c76ae28cf890f99c5715a7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:34",
            "last_seen_utc": "2026-10-10 21:08:52",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959678": [
        {
            "ioc_value": "2f7bed0fbc7213a208bbad89420a87038502573931cf95def6200bdebc2438fd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:33",
            "last_seen_utc": "2026-10-10 21:09:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959677": [
        {
            "ioc_value": "fe09cdce35bf1e733433fcc3b1e89938d2792478927f796d0bdc5bc44d5668b5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:32",
            "last_seen_utc": "2026-10-10 21:08:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959676": [
        {
            "ioc_value": "a887dc49c2aa5ab19f20a2c1e9f9ad73d303633c312e610aaf50cc81a823d8cf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:31",
            "last_seen_utc": "2026-10-10 21:08:45",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959675": [
        {
            "ioc_value": "0a23fe83d1e222a8682138527fa9132e6f1719789b434e4ef74b27642e506238",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:29",
            "last_seen_utc": "2026-10-10 21:09:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959674": [
        {
            "ioc_value": "a682198c4651b295214b1daec65399df98a936465f8e954735782532441e525f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:28",
            "last_seen_utc": "2026-10-10 21:08:53",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959673": [
        {
            "ioc_value": "1ead4bb085c60303c60b87866feae102400f562743e0a2ef43eb13506ec11aa1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:12:27",
            "last_seen_utc": "2026-10-10 21:09:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959671": [
        {
            "ioc_value": "64.190.113.163:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-10 01:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959657": [
        {
            "ioc_value": "https://qris100gacor.space/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/qris100gacor.space",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959658": [
        {
            "ioc_value": "https://prediksi666slot.space/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/prediksi666slot.space",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959659": [
        {
            "ioc_value": "https://pragmaticwsg1st.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmaticwsg1st.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959660": [
        {
            "ioc_value": "https://rajaslot321.site/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rajaslot321.site",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959661": [
        {
            "ioc_value": "https://rajaslot777.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rajaslot777.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959662": [
        {
            "ioc_value": "https://rajaslot777win.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rajaslot777win.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959663": [
        {
            "ioc_value": "https://resulttopwin1st.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/resulttopwin1st.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959664": [
        {
            "ioc_value": "https://rupiahtogel77.space/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rupiahtogel77.space",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959665": [
        {
            "ioc_value": "https://rupiah155slot.space/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rupiah155slot.space",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959666": [
        {
            "ioc_value": "https://rupiahmahjong2.space/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rupiahmahjong2.space",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959667": [
        {
            "ioc_value": "https://rupiahtotal10k.online/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rupiahtotal10k.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959668": [
        {
            "ioc_value": "https://wecarehairstudio.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wecarehairstudio.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959669": [
        {
            "ioc_value": "https://yandexslot01.space/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/yandexslot01.space",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959651": [
        {
            "ioc_value": "https://pragmatic500jp.online/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmatic500jp.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959652": [
        {
            "ioc_value": "https://pragmaticgacor01.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmaticgacor01.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959653": [
        {
            "ioc_value": "https://pragmaticws1.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmaticws1.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959654": [
        {
            "ioc_value": "https://pragmaticme1k.cyou/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmaticme1k.cyou",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959655": [
        {
            "ioc_value": "https://pragmatic321.site/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmatic321.site",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959656": [
        {
            "ioc_value": "https://pragmaticgacor1.world/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 01:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pragmaticgacor1.world",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959646": [
        {
            "ioc_value": "furiousmiquela.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 00:52:24",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959643": [
        {
            "ioc_value": "13f33a61.pattysole.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-10 00:48:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959642": [
        {
            "ioc_value": "76.92.216.35.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-10 00:40:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959639": [
        {
            "ioc_value": "brows-check.codes",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-10 00:33:23",
            "last_seen_utc": "2026-10-10 08:32:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959633": [
        {
            "ioc_value": "https://zeus773jpe.online/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/zeus773jpe.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959634": [
        {
            "ioc_value": "https://zeus138.co/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/zeus138.co",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959635": [
        {
            "ioc_value": "https://ysense.pro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/ysense.pro",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959636": [
        {
            "ioc_value": "https://blackiron.co.uk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/blackiron.co.uk",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959637": [
        {
            "ioc_value": "https://zapxa.com/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/zapxa.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959638": [
        {
            "ioc_value": "https://zeus138.ink/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:30:55",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/zeus138.ink",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959631": [
        {
            "ioc_value": "http://72.255.26.71:34632/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 00:19:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/72.255.26.71",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959632": [
        {
            "ioc_value": "http://36.255.33.195:35288/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 00:19:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/36.255.33.195",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959630": [
        {
            "ioc_value": "http://14.205.104.200:56814/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-10 00:19:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/14.205.104.200",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1959629": [
        {
            "ioc_value": "b992e0488abed5c19f215626dee38cc4b7b92b918ab194e276924a462aa97c3f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-10 00:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Bashlite,elf,Gafgyt",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959628": [
        {
            "ioc_value": "98792483aed3a9e0105cdaca1d5208916c07c45e0c46229e221a753fe3db0d30",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai,wraith",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959627": [
        {
            "ioc_value": "d59a4194ec66b508697d67d71b69f74f590e8a8bb346507075b3ded56854a374",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-10 00:12:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Bashlite,elf,Gafgyt",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959626": [
        {
            "ioc_value": "d3d562dd6dd1ab9eb00c129df63bd410af9559de00a2221f4b82f29c98072131",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959625": [
        {
            "ioc_value": "799fa192a037ebd85c4952a9a5efea5642b0374562e1e1e78b18f28a8d867660",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959624": [
        {
            "ioc_value": "1b87f5059a288b9bf34981dfd33a3309feb7eeaa7d7d33f257d18eefd9b2813b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959623": [
        {
            "ioc_value": "9b80ba79e0a98a33a32d987715362c83899ef944546889e7fcd46d34ff6f30b6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959621": [
        {
            "ioc_value": "39fca907066ee462356b2a30cca683d480bee773fd4f4de45898c060faa7294a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959622": [
        {
            "ioc_value": "33128cebb2c08acc3dcf0856c25768782f9a965aca8fd5ff86a4b3f647f6b7df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959620": [
        {
            "ioc_value": "aaa6922446155239a1cbab668d42117f234d024da7345aac83e4b2537eba7157",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959619": [
        {
            "ioc_value": "eabdfff5e2978a124bbdbcab9d50de7e9babfd03ea0a4ef6a1f408b62b6467f7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959618": [
        {
            "ioc_value": "9ed835a766588d2c40d369bd677ba4893b98dcc6104e8096c16659fb720727cc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-10 00:12:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959589": [
        {
            "ioc_value": "https://sayeedafzalkhan.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/sayeedafzalkhan.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959590": [
        {
            "ioc_value": "https://saascription.app/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/saascription.app",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959591": [
        {
            "ioc_value": "https://sa1-sharepoint.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/sa1-sharepoint.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959592": [
        {
            "ioc_value": "https://saltrans.ro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/saltrans.ro",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959593": [
        {
            "ioc_value": "https://saimonabdullah.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/saimonabdullah.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959594": [
        {
            "ioc_value": "https://supremelabbd.com/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/supremelabbd.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959595": [
        {
            "ioc_value": "https://tealnetwork.biz/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/tealnetwork.biz",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959596": [
        {
            "ioc_value": "https://upvod.net/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/upvod.net",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959597": [
        {
            "ioc_value": "https://varnixboya.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/varnixboya.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959598": [
        {
            "ioc_value": "https://uttejpalavai.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/uttejpalavai.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959599": [
        {
            "ioc_value": "https://voiceofthesun.com/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/voiceofthesun.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959600": [
        {
            "ioc_value": "https://wakanda123king.shop/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wakanda123king.shop",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959601": [
        {
            "ioc_value": "https://worldgo.online/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/worldgo.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959602": [
        {
            "ioc_value": "https://www88vv.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www88vv.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959603": [
        {
            "ioc_value": "https://www82live.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www82live.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959604": [
        {
            "ioc_value": "https://saferyalla.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/saferyalla.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959605": [
        {
            "ioc_value": "https://waitservices.co.uk/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/waitservices.co.uk",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959606": [
        {
            "ioc_value": "https://wakanda123plays.info/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wakanda123plays.info",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959607": [
        {
            "ioc_value": "https://wakandaasia.online/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wakandaasia.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959608": [
        {
            "ioc_value": "https://wakanda123us.store/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wakanda123us.store",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959609": [
        {
            "ioc_value": "https://wesolveit.pt/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wesolveit.pt",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959610": [
        {
            "ioc_value": "https://worldtripora.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/worldtripora.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959611": [
        {
            "ioc_value": "https://wibestgh.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/wibestgh.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959612": [
        {
            "ioc_value": "https://yogitaelegantbeauty.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/yogitaelegantbeauty.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959613": [
        {
            "ioc_value": "https://yalla5shoot.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/yalla5shoot.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959614": [
        {
            "ioc_value": "https://yauvanpower.online/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/yauvanpower.online",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959615": [
        {
            "ioc_value": "https://ylevents.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/ylevents.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959616": [
        {
            "ioc_value": "https://yj2005.net/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/yj2005.net",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959617": [
        {
            "ioc_value": "https://ymusic.id/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-10 00:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/ymusic.id",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959588": [
        {
            "ioc_value": "google-proxy-66-249-88-99.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 23:55:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959577": [
        {
            "ioc_value": "https://rentaride.top/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rentaride.top",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959578": [
        {
            "ioc_value": "https://rivlet.pro/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rivlet.pro",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959579": [
        {
            "ioc_value": "https://resianenterprisesltd.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/resianenterprisesltd.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959580": [
        {
            "ioc_value": "https://rootsinfosoft.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rootsinfosoft.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959581": [
        {
            "ioc_value": "https://www.synnersys.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/www.synnersys.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959582": [
        {
            "ioc_value": "https://roundcube-panel.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/roundcube-panel.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959583": [
        {
            "ioc_value": "https://royalxcasino.zone/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/royalxcasino.zone",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959584": [
        {
            "ioc_value": "https://roze.click/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/roze.click",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959585": [
        {
            "ioc_value": "https://ruchameditech.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/ruchameditech.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959586": [
        {
            "ioc_value": "https://upsurge.solutions/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/upsurge.solutions",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959587": [
        {
            "ioc_value": "https://rumsontrading.co.zw/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rumsontrading.co.zw",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959564": [
        {
            "ioc_value": "https://prognosisinfo.in/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/prognosisinfo.in",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959565": [
        {
            "ioc_value": "https://primemobilelv.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/primemobilelv.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959566": [
        {
            "ioc_value": "https://pudamponorogo.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pudamponorogo.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959567": [
        {
            "ioc_value": "https://primescaffolding.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/primescaffolding.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959568": [
        {
            "ioc_value": "https://radcomm.co.id/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/radcomm.co.id",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959569": [
        {
            "ioc_value": "https://radcomm.net.id/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/radcomm.net.id",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959570": [
        {
            "ioc_value": "https://programakuntansi.id/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/programakuntansi.id",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959571": [
        {
            "ioc_value": "https://project.pm/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/project.pm",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959572": [
        {
            "ioc_value": "https://rafacommunications.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rafacommunications.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959573": [
        {
            "ioc_value": "https://rapideex.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rapideex.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959574": [
        {
            "ioc_value": "https://pythonmania.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/pythonmania.org",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959575": [
        {
            "ioc_value": "https://raliz.one/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/raliz.one",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959576": [
        {
            "ioc_value": "https://rawatcoedcollege.com/cgi-sys/defaultwebpage.cgi",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 23:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rawatcoedcollege.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959563": [
        {
            "ioc_value": "ohetl1ri2c.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 23:29:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959561": [
        {
            "ioc_value": "purizezo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 23:17:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959560": [
        {
            "ioc_value": "9080cd485a8b94742cce721c63ffd0266ee9b3684e48165db8b6b12e0d181760",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959559": [
        {
            "ioc_value": "fe1d7aedc8ebd2976e1c7041a6982635698cc77e93eeea12a844f4ce06e620b1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959558": [
        {
            "ioc_value": "a527b6aee124dba9df0ece29610bc141bf532075189e0d62a7e26f343844f867",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959557": [
        {
            "ioc_value": "1e76392a5f25bd9700b38d164be21c42946d3ef5a6bdc906093d9ebf9da6574b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959556": [
        {
            "ioc_value": "465356f33b322c3f0aa694c8db805ee97ae1f278191e215468f9c10ec5a60ae1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959555": [
        {
            "ioc_value": "17fcb5d7d251b9684177a28843a4aaaee86539469ad20de3deb2063ee18ed63a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959554": [
        {
            "ioc_value": "e3923ff4e583f2860938954ae43f3abbd7b1f09b59528b1b53dafd1ad768cec8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959553": [
        {
            "ioc_value": "b9735080d510c445d40bca028c9eff7a56fbf571f5b24e50511f4d71e3ed5d15",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959552": [
        {
            "ioc_value": "d58ed4e7cf9ab3181cb59e18050cd9d4c41b334f0f07be08abe5bafed5c04069",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959551": [
        {
            "ioc_value": "5003d4cf1849fc207f3023b7220800f998cc34ec416ca3525f2707711258b98a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959550": [
        {
            "ioc_value": "3e724458a4b817aad81a70746f397fc4830da3ab02d465f53dcf8e6af9a8391e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959549": [
        {
            "ioc_value": "56c17e283d9349a7d46a01f52ee8d4892d69e57cb722e9dab01f771aa2bf6783",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959548": [
        {
            "ioc_value": "34ae6b0ab55c1caf55b556cc3f0a85af03586fa7861a64112a49a7258d69709f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959547": [
        {
            "ioc_value": "8f257396b6c3472702d7562d6e5ac4b869de4039954db5991139ca5ae00de30a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959546": [
        {
            "ioc_value": "627f383e146ccc663d2d88a6b765330b181bf0b197ccc4510540d283e41a5704",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959545": [
        {
            "ioc_value": "09e9d8b33d642f842776f533c84c8babf7b0af0c5fbdf64d01fad282b5556a7f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959544": [
        {
            "ioc_value": "9f04d8622216750884fe7779ea833b37f1c1670a88dc88041a5cbf695bc2dd31",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959543": [
        {
            "ioc_value": "d32393f0c64660baab8974eda993fff837c24a3ec296bbfc302a4f6e3a5a305b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959542": [
        {
            "ioc_value": "b694d9c69417fe8514f2ab80e7f73af18e0653ca774e4eb14c74a3775d69cc4a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-09 23:12:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Bashlite,Gafgyt,sh",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959541": [
        {
            "ioc_value": "3546decb71e68e56654a25a82960424d19df7e04e9b0481d12b2c7d4c9f79eb3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959540": [
        {
            "ioc_value": "8e5ff8ee8ce085f5e2c7ca1f4f0b9d604e4bd4240ad452b46242ba9d12e2c684",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959539": [
        {
            "ioc_value": "dcb73c8bd1e3f1caa88e6ca0c4df75e3dba480a8ba88d8b22bbaff095b9b2381",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959538": [
        {
            "ioc_value": "dfa5758cd0b07e380df4a5067a7c18779c1b99f352ae747a25b6fc3f24469d6a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959537": [
        {
            "ioc_value": "363d7f945d3ffc0ec2d67154b0a552f322ea562a608924a98cf5c44388cc8dc3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959536": [
        {
            "ioc_value": "10748c67616223ab0c72cfddaf274fa45e685221d20bcc20d79b17ff410fdc07",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959535": [
        {
            "ioc_value": "675546ace447fa3dbb79971bda65c7263e823c328ade35cc3d623ef73c301583",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959534": [
        {
            "ioc_value": "f9186adf5ca7b6815f1b0d1307210b40fa046618134d17b017bcab65a034d1d4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959533": [
        {
            "ioc_value": "969c0b27614d262367434b7b1451547285c36c0f69818ce0692ee4d28474a09b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959532": [
        {
            "ioc_value": "d2fb1489eb4aa374a78fd3a2d96ca211976e0d84742e3c90864e2b5eb1c65f83",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959531": [
        {
            "ioc_value": "46525da46c4e20231916e3c4bac20cbc6156035bc578a3268afac9311daa9585",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 23:12:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959530": [
        {
            "ioc_value": "8f3ddbc6090f6bbb75805de8ca284953696e283b438cfa9a45c3713c6ebcb70c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.santa_stealer",
            "malware_alias": null,
            "malware_printable": "SantaStealer",
            "first_seen_utc": "2026-10-09 23:12:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,SantaStealer,stealer",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959529": [
        {
            "ioc_value": "http://102.212.61.41:8025/sshd",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.sshdoor",
            "malware_alias": null,
            "malware_printable": "SSHDoor",
            "first_seen_utc": "2026-10-09 23:08:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "elf,SSHdKit,SSHDoor",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959528": [
        {
            "ioc_value": "f81503e8.b00kself.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 23:08:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959527": [
        {
            "ioc_value": "bf5f2f9e.b00kself.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 23:08:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959526": [
        {
            "ioc_value": "google-proxy-66-249-88-100.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 22:51:29",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959525": [
        {
            "ioc_value": "google-proxy-66-249-88-229.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 22:42:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959521": [
        {
            "ioc_value": "zyxube.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 22:27:13",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959520": [
        {
            "ioc_value": "31.56.19.111:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-09 22:26:32",
            "last_seen_utc": "2026-10-10 22:32:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1959517": [
        {
            "ioc_value": "https://kertc4.website/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 22:22:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "WARDENStealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1959518": [
        {
            "ioc_value": "https://lemanruss4.website/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 22:22:23",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "WARDENStealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1959516": [
        {
            "ioc_value": "ecned5tg.roseanne.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 22:19:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959512": [
        {
            "ioc_value": "51b2a2243840c0681167405e2ebbf9f5ac05105f94dc005d335897952d962224",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959511": [
        {
            "ioc_value": "d724dc8b5d6bb230f42a3ec0d5f71ccb8c8e9a88025756074b36961709ed1384",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959510": [
        {
            "ioc_value": "e867fc47c809868e46bbef459c4146b0ed111697d7672ce4c6623322afa2a1f4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959509": [
        {
            "ioc_value": "384b954cd0b20f18eb7b3efbf98e0a1c6e7f599e73800ffd44f89a48e3156c5c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959508": [
        {
            "ioc_value": "60324938d01641de82b11bd0fd91d10f93f9b79bc40f031709d82337fb8a241e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959507": [
        {
            "ioc_value": "9303a4a918d93f360dc885fcaa68a50e021362e3b182d4ffd176eba4d6118203",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959506": [
        {
            "ioc_value": "a38d9d55a54179e26ec9031764a623b25282f55080329702affacd795621d4df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 22:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959505": [
        {
            "ioc_value": "78eda3158bc47d7d0982c476486b12faaf6e46195e0bfc457c8ed43690f0de82",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.svcstealer",
            "malware_alias": null,
            "malware_printable": "SVCStealer",
            "first_seen_utc": "2026-10-09 22:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "579cd0,cred.dll,dll,dropped-by-Amadey,exe,plugin,stealer,SVCStealer",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959504": [
        {
            "ioc_value": "171785acdb1595e6a4d2fc0a2a153895b1ebfd75b9dcfb30c8ffa43885abbf58",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.xorddos",
            "malware_alias": "XORDDOS",
            "malware_printable": "XOR DDoS",
            "first_seen_utc": "2026-10-09 22:12:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,XORDDoS",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959503": [
        {
            "ioc_value": "2b263e84b679f604988922f3ad5928c68be97e3ffe305d1fad4e2b7623815b9d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.smartloader",
            "malware_alias": null,
            "malware_printable": "SmartLoader",
            "first_seen_utc": "2026-10-09 22:12:26",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "dropper,loader,SmartLoader,trojan,zip",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959502": [
        {
            "ioc_value": "http://154.91.180.246:18080/?h=154.91.180.246&p=18080&t=tcp&a=w64&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 22:08:27",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959501": [
        {
            "ioc_value": "http://154.91.180.246:18080/?h=154.91.180.246&p=18080&t=ws&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 22:08:26",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959500": [
        {
            "ioc_value": "http://derelb.shop:3781",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-09 22:06:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1959498": [
        {
            "ioc_value": "76dlzuzd.pinke.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 21:57:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959491": [
        {
            "ioc_value": "groupby.careers",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 21:44:41",
            "last_seen_utc": "2026-10-09 22:38:26",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959492": [
        {
            "ioc_value": "includetraining.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 21:44:41",
            "last_seen_utc": "2026-10-09 22:17:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959488": [
        {
            "ioc_value": "mugico.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 21:18:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959487": [
        {
            "ioc_value": "fern-roam-moss-luio.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:17:55",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959486": [
        {
            "ioc_value": "6394596ffddbf240d0ec2584c2d66984f1cb415f7d440d9b29b04d58b8e0fbcc",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959485": [
        {
            "ioc_value": "b38ed72f2f3f4764e3d0c6e12d574e0754fe29729f247087c1e8314c9156e77c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959484": [
        {
            "ioc_value": "7309360ac07a489a256e64fc4221b4f08aab4263b487bc6831acc11c8e75c012",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "cowrie,elf,Gafgyt,honeypot,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959483": [
        {
            "ioc_value": "75b4aaa700bec8144f5a30708fb10058b165d41034e7323c34f5f4bedead84a1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959482": [
        {
            "ioc_value": "1981072e76c686dacae199ef1df3485874d3af313ec2203f32182019c110eb4b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959481": [
        {
            "ioc_value": "25089d27e69ec64c5d5887f8f67303db883fe0c373df6a8805ad960a313b1777",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959480": [
        {
            "ioc_value": "2c24769688bb6658599eed56478b3320d32d79a55da0da144079c146b7ea82d4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959479": [
        {
            "ioc_value": "256d18fb82f5f09352f3fab80b9a759d1a477704aa901dc355607350c17714d4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959478": [
        {
            "ioc_value": "ce61e0ca3ab45a208d25be45629241517f2049b02155f0435bd04e1b409c892c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959477": [
        {
            "ioc_value": "7c78a7534a25396301040953b5f3ec1fb5b142e9b60f98cc6933b4a97bb3d42e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Gafgyt,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959476": [
        {
            "ioc_value": "49963c85538f250aa56323d18d455b3ee7bf8476fecbaa08288f43611d325d6a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959475": [
        {
            "ioc_value": "49f0660e44d1335fb9828d57cc9930122a355d36e6a3bc5892066d6fde815b5d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959474": [
        {
            "ioc_value": "d0122373c21acfb3dce53eca64d5377c8b2f25b8a3596c3299cf592d8b2ff279",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959473": [
        {
            "ioc_value": "c0863e8dbb46099ae4897fbdbf2dac14e0e2e2871d0595ee38d37b3fc44f3b36",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959472": [
        {
            "ioc_value": "17d0b378447464b9fb008ed7fa1093cfad9ace3bd730ed12e4716500001fddfa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959471": [
        {
            "ioc_value": "67daf40b1926496df5284a89925803c3b8afa8e86caea1c2500e7877ef8ad6d6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959470": [
        {
            "ioc_value": "7aebcb45ba36a05af1e1417d4684177bae1bde9d05108f28838d0b510302bd0e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959469": [
        {
            "ioc_value": "8abcd362bf46284f62bfdcf17d8bb133810c8a2d56ac3250672e57863dcf5b0f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959468": [
        {
            "ioc_value": "3843e3cb7c53702c947b3ee09a364e57c3594bb66e754446544a266e9fb1c927",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959467": [
        {
            "ioc_value": "613853e3c95f8c9d4c7e47b398277f56b135d29f0d7ccc1b7b93991dbeb1d5e5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959466": [
        {
            "ioc_value": "bb2486cc8b29aca9eb8221a247c309b77445284ca088d9249bc51032aaf17447",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959465": [
        {
            "ioc_value": "6fb1a5b3ae48d16378c147932cafbc8ee2749742660cfc2030ea5ebfea25fc96",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959464": [
        {
            "ioc_value": "224eaf712bb4e7e7788a9a044eededf850423de3ff3c57c1f9bddb9c5d31430f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959463": [
        {
            "ioc_value": "8abb1acdd04b0f3033dc98f52e27cd5abd962087a09b6f309a5d17d5f203f388",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959462": [
        {
            "ioc_value": "37530b711f22e6fd20ecad05961fa5fd6ee6afa2e60ab01931bda4819c4229ba",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:28",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959461": [
        {
            "ioc_value": "dbe8e30860c8fc4f1470138113f3ea1983129319938b3bb98f3616df0ac23f01",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959460": [
        {
            "ioc_value": "01d405d38a39cd42c105fbcba6ac43fd635ab2a15a8b4c2708de4911a85ea2e8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959459": [
        {
            "ioc_value": "e0e3bc074110f890e105adc5b8c3a37be65afa99d99c7e3733bf46e22a372591",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:25",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959458": [
        {
            "ioc_value": "6a3484acaf85a596be22daad188e736e9961ad1f56729153f404bb5434988c00",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959457": [
        {
            "ioc_value": "9ed373c6ca5485a21fe6c7a43acf56b307d37ecb89cbf9cb0775a417c77faa00",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 21:12:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959456": [
        {
            "ioc_value": "5a3541e4dd89bc89772df74147d5e5f64e57eedd4a359b0b38cfe2167131af6c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959455": [
        {
            "ioc_value": "ea6469f084d3846554c7864989a74dcbe8e1e61505ee6071f4ae3f2496b5c34b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959454": [
        {
            "ioc_value": "669fc45dad88823fc40d84b875351fa206c9dcc05d8046e396a8dfcbc21f5651",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959453": [
        {
            "ioc_value": "0ec78298a3a2f65f9b0481623638eb4e09c039d9792c6a17d0910f8209046cbb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,Ngioweb,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959452": [
        {
            "ioc_value": "96d903df987d479d1e7879a4d869c292b8f887c800959221fd42399a0108f198",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959451": [
        {
            "ioc_value": "3ecb803d857410ee17b3296a92e4ea6a208bb7569f10eb68901fbb8a267dbb38",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959450": [
        {
            "ioc_value": "c6bf49be04e832e4c35a2c49559f4978c9bc9ebcc47878d0ce494fcc5efbe593",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959449": [
        {
            "ioc_value": "dbecfa96a453103f2503bb3d7376c43347d4c9520efb5be864626d2ee1ca8490",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959448": [
        {
            "ioc_value": "383fde5c88928a74c530f2e1e84007f9a7c70b980a002894b4f2f3b575c3b1db",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-09 21:12:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Bashlite,elf,Gafgyt,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959447": [
        {
            "ioc_value": "90438e02b7f3d87ba0d832308efe5f20d895713d52f614fd98e7fc3eb643b3b9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959446": [
        {
            "ioc_value": "6fb593f99acb421d91f864e01d61c65ab5c775aa92b96ca7c538785682974125",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959445": [
        {
            "ioc_value": "a6f47b9728c0bf44140e9f561ae885740f8fcc7afecef9f072b1900180fad2a7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 21:12:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959444": [
        {
            "ioc_value": "mojixovo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 21:11:50",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959440": [
        {
            "ioc_value": "http://148.66.17.125:60003/?h=148.66.17.125&p=60003&t=tcp&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 21:07:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,VShell",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959439": [
        {
            "ioc_value": "https://aldefix.com/aldefix.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 21:06:07",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,RustyStealer,stealer",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959438": [
        {
            "ioc_value": "189.249.195.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 21:05:04",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959424": [
        {
            "ioc_value": "yauvanpower.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959425": [
        {
            "ioc_value": "yj2005.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959426": [
        {
            "ioc_value": "ylevents.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959427": [
        {
            "ioc_value": "ymusic.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959428": [
        {
            "ioc_value": "yogitaelegantbeauty.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-10 14:54:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959429": [
        {
            "ioc_value": "youssefragab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959430": [
        {
            "ioc_value": "ysense.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959431": [
        {
            "ioc_value": "z5cable.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959432": [
        {
            "ioc_value": "zapxa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959433": [
        {
            "ioc_value": "zeus138.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959434": [
        {
            "ioc_value": "zeus138.ink",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:07:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959435": [
        {
            "ioc_value": "zeus773jpe.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:17:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959436": [
        {
            "ioc_value": "zonainfo.biz.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:52",
            "last_seen_utc": "2026-10-09 21:17:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959397": [
        {
            "ioc_value": "tusometech.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959398": [
        {
            "ioc_value": "ufaxs.bet",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 00:14:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959399": [
        {
            "ioc_value": "upsurge.solutions",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:17:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959400": [
        {
            "ioc_value": "upvod.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959401": [
        {
            "ioc_value": "uttejpalavai.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 02:29:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959402": [
        {
            "ioc_value": "varnixboya.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 02:30:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959403": [
        {
            "ioc_value": "vebiotic.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 02:29:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959404": [
        {
            "ioc_value": "venom189.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 02:29:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959405": [
        {
            "ioc_value": "voiceofthesun.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959406": [
        {
            "ioc_value": "waitservices.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:17:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959407": [
        {
            "ioc_value": "wakanda123king.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 02:29:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959408": [
        {
            "ioc_value": "wakanda123plays.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959409": [
        {
            "ioc_value": "wakanda123us.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959410": [
        {
            "ioc_value": "wakandaasia.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959411": [
        {
            "ioc_value": "warungseblak.co.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:17:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959412": [
        {
            "ioc_value": "wecarehairstudio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:17:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959413": [
        {
            "ioc_value": "welespoken.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 22:17:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959414": [
        {
            "ioc_value": "wesolveit.pt",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959415": [
        {
            "ioc_value": "wibestgh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959416": [
        {
            "ioc_value": "woles189.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959417": [
        {
            "ioc_value": "worldgo.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 02:30:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959418": [
        {
            "ioc_value": "worldtripora.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-10 14:54:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959419": [
        {
            "ioc_value": "ww2clash.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:17:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959420": [
        {
            "ioc_value": "www82live.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959421": [
        {
            "ioc_value": "www88vv.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959422": [
        {
            "ioc_value": "yalla5shoot.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-09 21:07:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959423": [
        {
            "ioc_value": "yandexslot01.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:51",
            "last_seen_utc": "2026-10-11 01:24:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959393": [
        {
            "ioc_value": "supremelabbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959394": [
        {
            "ioc_value": "synnersys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959395": [
        {
            "ioc_value": "tealnetwork.biz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959396": [
        {
            "ioc_value": "theacosta.house",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:50",
            "last_seen_utc": "2026-10-10 00:04:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959365": [
        {
            "ioc_value": "rcschoudhary.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959366": [
        {
            "ioc_value": "reallymake.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959367": [
        {
            "ioc_value": "rebakagit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959368": [
        {
            "ioc_value": "rentaride.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 02:07:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959369": [
        {
            "ioc_value": "rescuekings.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959370": [
        {
            "ioc_value": "resianenterprisesltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 02:07:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959371": [
        {
            "ioc_value": "resulttopwin1st.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959372": [
        {
            "ioc_value": "rivlet.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 02:27:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959373": [
        {
            "ioc_value": "rmfx.limited",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-09 22:17:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959374": [
        {
            "ioc_value": "rootsinfosoft.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 00:04:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959375": [
        {
            "ioc_value": "roundcube-panel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-09 23:53:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959376": [
        {
            "ioc_value": "royalxcasino.zone",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-09 23:53:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959377": [
        {
            "ioc_value": "roze.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-09 23:54:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959378": [
        {
            "ioc_value": "rtm7tech.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959379": [
        {
            "ioc_value": "ruchameditech.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 00:14:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959380": [
        {
            "ioc_value": "rumsontrading.co.zw",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 00:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959381": [
        {
            "ioc_value": "rupiah155slot.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959382": [
        {
            "ioc_value": "rupiahmahjong2.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-11 02:08:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959383": [
        {
            "ioc_value": "rupiahtogel77.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959384": [
        {
            "ioc_value": "rupiahtops1stwin.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959385": [
        {
            "ioc_value": "rupiahtotal10k.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-11 01:24:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959386": [
        {
            "ioc_value": "sa1-sharepoint.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959387": [
        {
            "ioc_value": "saascription.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-09 23:54:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959388": [
        {
            "ioc_value": "saferyalla.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 14:53:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959389": [
        {
            "ioc_value": "saimonabdullah.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 00:04:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959390": [
        {
            "ioc_value": "saltrans.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-09 23:53:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959391": [
        {
            "ioc_value": "sassythesongstress.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": "2026-10-10 00:04:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959392": [
        {
            "ioc_value": "sayeedafzalkhan.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959337": [
        {
            "ioc_value": "pragmatic222gac0r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959338": [
        {
            "ioc_value": "pragmatic321.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959339": [
        {
            "ioc_value": "pragmatic500jp.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959340": [
        {
            "ioc_value": "pragmaticgacor01.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959341": [
        {
            "ioc_value": "pragmaticgacor1.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959342": [
        {
            "ioc_value": "pragmaticme1k.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959343": [
        {
            "ioc_value": "pragmaticws1.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959344": [
        {
            "ioc_value": "pragmaticwsg1st.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959345": [
        {
            "ioc_value": "prediksi666slot.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959346": [
        {
            "ioc_value": "primemobilelv.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959347": [
        {
            "ioc_value": "primescaffolding.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959348": [
        {
            "ioc_value": "prognosisinfo.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959349": [
        {
            "ioc_value": "programakuntansi.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 00:04:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959350": [
        {
            "ioc_value": "project.pm",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 00:04:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959351": [
        {
            "ioc_value": "pudamponorogo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-09 23:24:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959352": [
        {
            "ioc_value": "pythonmania.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 02:27:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959353": [
        {
            "ioc_value": "qris100gacor.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959354": [
        {
            "ioc_value": "radcomm.co.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-09 23:24:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959355": [
        {
            "ioc_value": "radcomm.net.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 02:27:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959356": [
        {
            "ioc_value": "radianhealthcare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959357": [
        {
            "ioc_value": "rafacommunications.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 02:07:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959358": [
        {
            "ioc_value": "rajaslot321.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959359": [
        {
            "ioc_value": "rajaslot777.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959360": [
        {
            "ioc_value": "rajaslot777win.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959361": [
        {
            "ioc_value": "raliz.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 02:27:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959362": [
        {
            "ioc_value": "rapideex.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 02:27:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959363": [
        {
            "ioc_value": "raranoodles.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959364": [
        {
            "ioc_value": "rawatcoedcollege.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:48",
            "last_seen_utc": "2026-10-10 02:07:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959307": [
        {
            "ioc_value": "openreader3.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959308": [
        {
            "ioc_value": "operalog.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959309": [
        {
            "ioc_value": "orionstrategyconsulting.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959310": [
        {
            "ioc_value": "ovotops1stwin.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959311": [
        {
            "ioc_value": "paitojitu2025.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959312": [
        {
            "ioc_value": "pak111.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959313": [
        {
            "ioc_value": "pak33.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959314": [
        {
            "ioc_value": "palmettoshopper.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959315": [
        {
            "ioc_value": "parlouredshop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959316": [
        {
            "ioc_value": "pecuweb.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959317": [
        {
            "ioc_value": "pendantpublishing.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959318": [
        {
            "ioc_value": "peykanrapkon.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959319": [
        {
            "ioc_value": "pgslotgacor1.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959320": [
        {
            "ioc_value": "pgsoft88gac0r.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959321": [
        {
            "ioc_value": "pgsoftgacor1.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959322": [
        {
            "ioc_value": "phoenixrehabservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959323": [
        {
            "ioc_value": "pipparrot.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959324": [
        {
            "ioc_value": "pirihuntingsafari.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959325": [
        {
            "ioc_value": "pk365.ac.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959326": [
        {
            "ioc_value": "pk88vn.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959327": [
        {
            "ioc_value": "pkrspin.web.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959328": [
        {
            "ioc_value": "playgame.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959329": [
        {
            "ioc_value": "poeirahistoria.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959330": [
        {
            "ioc_value": "pojok.biz.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959331": [
        {
            "ioc_value": "popupsure.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959332": [
        {
            "ioc_value": "porticoesquadrias.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959333": [
        {
            "ioc_value": "pos47.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959334": [
        {
            "ioc_value": "pragmatic1000win.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959335": [
        {
            "ioc_value": "pragmatic111gac0r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959336": [
        {
            "ioc_value": "pragmatic1jepe.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959278": [
        {
            "ioc_value": "mmgamingpal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959279": [
        {
            "ioc_value": "moneysense.cloud",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959280": [
        {
            "ioc_value": "mortal78.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959281": [
        {
            "ioc_value": "motowin77login.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959282": [
        {
            "ioc_value": "mozafari.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959283": [
        {
            "ioc_value": "mufasatotoya.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959284": [
        {
            "ioc_value": "multigroup.co.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959285": [
        {
            "ioc_value": "murat.ink",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959286": [
        {
            "ioc_value": "mustleadschools.ac.tz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959287": [
        {
            "ioc_value": "my4e.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959288": [
        {
            "ioc_value": "myflowermoon.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959289": [
        {
            "ioc_value": "narailexpress.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959290": [
        {
            "ioc_value": "narativa-x.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959291": [
        {
            "ioc_value": "natsav.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959292": [
        {
            "ioc_value": "nevadamarijuanacard.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959293": [
        {
            "ioc_value": "newsstarlinkhindi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959294": [
        {
            "ioc_value": "nightbezel-ext.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959295": [
        {
            "ioc_value": "nullro.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959296": [
        {
            "ioc_value": "officialkeren777.hair",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959297": [
        {
            "ioc_value": "oilpalmconsultant.co.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959298": [
        {
            "ioc_value": "olympus01gacors.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959299": [
        {
            "ioc_value": "olympus1gacors.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959300": [
        {
            "ioc_value": "olympus4asli.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959301": [
        {
            "ioc_value": "olympusgac0rwin.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959302": [
        {
            "ioc_value": "onecollect.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959303": [
        {
            "ioc_value": "onestopanalytical.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959304": [
        {
            "ioc_value": "onestoprealtygy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959305": [
        {
            "ioc_value": "onlineapps.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959306": [
        {
            "ioc_value": "onlinetops1st.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959263": [
        {
            "ioc_value": "ligaciputra.bio",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959264": [
        {
            "ioc_value": "livesportsapi.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959265": [
        {
            "ioc_value": "llotestudio.com.ar",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959266": [
        {
            "ioc_value": "lxyapp.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959267": [
        {
            "ioc_value": "medinmoc.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959268": [
        {
            "ioc_value": "medsolutions360.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959269": [
        {
            "ioc_value": "megaslot8gac0r.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959270": [
        {
            "ioc_value": "megaways5000jp.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959271": [
        {
            "ioc_value": "megawin122.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959272": [
        {
            "ioc_value": "megawin888jp.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959273": [
        {
            "ioc_value": "melhores-casinos-pt-2026.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959274": [
        {
            "ioc_value": "menang120.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959275": [
        {
            "ioc_value": "mesin-gacor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959276": [
        {
            "ioc_value": "midhaterasool.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959277": [
        {
            "ioc_value": "miotogel.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959249": [
        {
            "ioc_value": "freecoupon.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959250": [
        {
            "ioc_value": "gmt-net.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959251": [
        {
            "ioc_value": "greentechs.com.bd",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959252": [
        {
            "ioc_value": "guia-casinos-portugal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959253": [
        {
            "ioc_value": "hominisbarbershop.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959254": [
        {
            "ioc_value": "iamshahid.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959255": [
        {
            "ioc_value": "intotain.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959256": [
        {
            "ioc_value": "ioss.si",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959257": [
        {
            "ioc_value": "j10.com.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959258": [
        {
            "ioc_value": "jackpot777jepe.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959259": [
        {
            "ioc_value": "jackpotmazze.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959260": [
        {
            "ioc_value": "janicevavra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959261": [
        {
            "ioc_value": "jormed.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959262": [
        {
            "ioc_value": "kndgas.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959237": [
        {
            "ioc_value": "danatoto11w.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959238": [
        {
            "ioc_value": "danatoto39top.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959239": [
        {
            "ioc_value": "demoslot250jt.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959240": [
        {
            "ioc_value": "ditinus.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959241": [
        {
            "ioc_value": "divara888.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959242": [
        {
            "ioc_value": "divara888.tech",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959243": [
        {
            "ioc_value": "divyajotifoundation.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959244": [
        {
            "ioc_value": "djeffker.cloud",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959245": [
        {
            "ioc_value": "dmsecommercepos.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959246": [
        {
            "ioc_value": "drdeepti.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959247": [
        {
            "ioc_value": "dytpelinsu.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959248": [
        {
            "ioc_value": "egeelectronic.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959222": [
        {
            "ioc_value": "bharatlivestock.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959223": [
        {
            "ioc_value": "bigbaji.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959224": [
        {
            "ioc_value": "bighoki1000jp.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959225": [
        {
            "ioc_value": "bighoki500jp.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959226": [
        {
            "ioc_value": "bigwin1000jp.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959227": [
        {
            "ioc_value": "blueideas.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959228": [
        {
            "ioc_value": "bluepage.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959229": [
        {
            "ioc_value": "bonanzaj3pe.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959230": [
        {
            "ioc_value": "bonanzajepe100jt.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959231": [
        {
            "ioc_value": "bosvip70wow.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959232": [
        {
            "ioc_value": "brightmarkconsultingltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959233": [
        {
            "ioc_value": "britflix-uk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959234": [
        {
            "ioc_value": "cafedebieb.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959235": [
        {
            "ioc_value": "champw.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959236": [
        {
            "ioc_value": "chicheritaradio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959202": [
        {
            "ioc_value": "aryarom.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959203": [
        {
            "ioc_value": "asm-app.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959204": [
        {
            "ioc_value": "azhentong111.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959205": [
        {
            "ioc_value": "baccarat01.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959206": [
        {
            "ioc_value": "basyoun.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959207": [
        {
            "ioc_value": "beatfocus.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959208": [
        {
            "ioc_value": "beatfocus.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959209": [
        {
            "ioc_value": "beatidea.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959210": [
        {
            "ioc_value": "beatinsights.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959211": [
        {
            "ioc_value": "beatpress.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959212": [
        {
            "ioc_value": "beatreader.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959213": [
        {
            "ioc_value": "beatscope.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959214": [
        {
            "ioc_value": "beatscribes.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959215": [
        {
            "ioc_value": "beatstories.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959216": [
        {
            "ioc_value": "beatwrites.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959217": [
        {
            "ioc_value": "beatwriting.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959218": [
        {
            "ioc_value": "bendingrealityinc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959219": [
        {
            "ioc_value": "bestsportsgearhub.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959220": [
        {
            "ioc_value": "beypazaribirtat.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959221": [
        {
            "ioc_value": "bharatlivestock.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959190": [
        {
            "ioc_value": "agenpers.quest",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959191": [
        {
            "ioc_value": "agenpez.quest",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959192": [
        {
            "ioc_value": "agenqez.quest",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959193": [
        {
            "ioc_value": "agenxexo.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959194": [
        {
            "ioc_value": "agenxox.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959195": [
        {
            "ioc_value": "agenxux.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959196": [
        {
            "ioc_value": "agenzzt.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959197": [
        {
            "ioc_value": "aichs365.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959198": [
        {
            "ioc_value": "aimdss.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959199": [
        {
            "ioc_value": "aisyadnm.sbs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959200": [
        {
            "ioc_value": "alexistotojp12jt.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959201": [
        {
            "ioc_value": "androidbaz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959170": [
        {
            "ioc_value": "222.blue",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959171": [
        {
            "ioc_value": "2in-sharepoint.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959172": [
        {
            "ioc_value": "889992769.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959173": [
        {
            "ioc_value": "889992924.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959174": [
        {
            "ioc_value": "889993536.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959175": [
        {
            "ioc_value": "a2ztraders.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959176": [
        {
            "ioc_value": "aac-news.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959177": [
        {
            "ioc_value": "aastitva.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959178": [
        {
            "ioc_value": "abc-tunnel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959179": [
        {
            "ioc_value": "abcfoods.mu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959180": [
        {
            "ioc_value": "abcplavani.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959181": [
        {
            "ioc_value": "abinteriors.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959182": [
        {
            "ioc_value": "absurd.africa",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959183": [
        {
            "ioc_value": "acarmanken.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959184": [
        {
            "ioc_value": "actionawe.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959185": [
        {
            "ioc_value": "adan.uy",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959186": [
        {
            "ioc_value": "aegp.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959187": [
        {
            "ioc_value": "aerogamingonline.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959188": [
        {
            "ioc_value": "agendaris.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959189": [
        {
            "ioc_value": "agendazt.quest",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:02:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959168": [
        {
            "ioc_value": "https://woostore.dev/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 21:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/woostore.dev",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959169": [
        {
            "ioc_value": "https://youssefragab.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 21:00:54",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/youssefragab.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959167": [
        {
            "ioc_value": "https://woles189.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 21:00:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/woles189.org",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959166": [
        {
            "ioc_value": "h78yoza9.miraz.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 21:00:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1959161": [
        {
            "ioc_value": "woostore.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:27",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959162": [
        {
            "ioc_value": "wibuku.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:27",
            "last_seen_utc": "2026-10-10 14:35:58",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959163": [
        {
            "ioc_value": "wertog.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:27",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959164": [
        {
            "ioc_value": "tubidy.study",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:27",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959165": [
        {
            "ioc_value": "ybpm-kudus.sch.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:27",
            "last_seen_utc": "2026-10-09 21:02:52",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959157": [
        {
            "ioc_value": "vlessi.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:26",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959158": [
        {
            "ioc_value": "vivekchaurasia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:26",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959159": [
        {
            "ioc_value": "tylertysdal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:26",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959160": [
        {
            "ioc_value": "wisebanq.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:26",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959156": [
        {
            "ioc_value": "websiteambition.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:57:25",
            "last_seen_utc": "2026-10-09 21:02:51",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959155": [
        {
            "ioc_value": "google-proxy-66-249-88-232.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 20:54:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959153": [
        {
            "ioc_value": "rickowenwear.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:47:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClearFake,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959142": [
        {
            "ioc_value": "transfy.cloud",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:23",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959143": [
        {
            "ioc_value": "throttletechnologies.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:23",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959144": [
        {
            "ioc_value": "tourdasgalaxias.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:23",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959145": [
        {
            "ioc_value": "tmd12.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959138": [
        {
            "ioc_value": "topvisionmarketing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:22",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959139": [
        {
            "ioc_value": "tizant.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:22",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959140": [
        {
            "ioc_value": "trussi-eg.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:22",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959141": [
        {
            "ioc_value": "trustawesome.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:22",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959134": [
        {
            "ioc_value": "thankgifts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:21",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959135": [
        {
            "ioc_value": "theglorius.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:21",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959136": [
        {
            "ioc_value": "trueloveksa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:21",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959137": [
        {
            "ioc_value": "tcsnt.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:21",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959131": [
        {
            "ioc_value": "taynguyenzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:20",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959132": [
        {
            "ioc_value": "toto10000idn.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:20",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959133": [
        {
            "ioc_value": "triplescenter.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:20",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959127": [
        {
            "ioc_value": "teiktok.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:19",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959128": [
        {
            "ioc_value": "toldosvenezuela.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:19",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959129": [
        {
            "ioc_value": "tortoisemmy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:19",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959130": [
        {
            "ioc_value": "threedollars.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:37:19",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959126": [
        {
            "ioc_value": "miraz.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:32:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1959124": [
        {
            "ioc_value": "sriharidasniwas.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:12",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959125": [
        {
            "ioc_value": "solutionscc.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:12",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959120": [
        {
            "ioc_value": "srthoster.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:11",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959121": [
        {
            "ioc_value": "solarandsafety.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:11",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959122": [
        {
            "ioc_value": "schwabfinancialcare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:11",
            "last_seen_utc": "2026-10-09 21:02:49",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959123": [
        {
            "ioc_value": "supermagnet.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:11",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959116": [
        {
            "ioc_value": "sitecctv.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:10",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959117": [
        {
            "ioc_value": "seven.com.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:10",
            "last_seen_utc": "2026-10-09 21:02:49",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959118": [
        {
            "ioc_value": "www.synnersys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959119": [
        {
            "ioc_value": "sileysewingmachines.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:10",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959112": [
        {
            "ioc_value": "tubidy.my",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:09",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959113": [
        {
            "ioc_value": "tr.xelorkesselhaus.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:09",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959114": [
        {
            "ioc_value": "tradeverge.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:09",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959115": [
        {
            "ioc_value": "stackdeans.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:09",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959109": [
        {
            "ioc_value": "trenz.biz.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:08",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959110": [
        {
            "ioc_value": "tradecom24.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:08",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959111": [
        {
            "ioc_value": "tcisbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:08",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959108": [
        {
            "ioc_value": "trendupdate.biz.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:22:07",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959106": [
        {
            "ioc_value": "soirise.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:04",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959107": [
        {
            "ioc_value": "silklubricant.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:04",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959103": [
        {
            "ioc_value": "slotteds.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:03",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959104": [
        {
            "ioc_value": "slotpk.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:03",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959105": [
        {
            "ioc_value": "spaceman333asli.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:03",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959101": [
        {
            "ioc_value": "shangrilavillageresort.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:02",
            "last_seen_utc": "2026-10-09 21:02:49",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959102": [
        {
            "ioc_value": "slot888asligac0r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:02",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959097": [
        {
            "ioc_value": "slot888gac0rvip.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:01",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959098": [
        {
            "ioc_value": "surkhabfabric.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:01",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959099": [
        {
            "ioc_value": "slot888pastijpe.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:01",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959100": [
        {
            "ioc_value": "spaceman01gacors.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:01",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959093": [
        {
            "ioc_value": "situstoto1.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:00",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959094": [
        {
            "ioc_value": "spaceman4asli.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:00",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959095": [
        {
            "ioc_value": "slot888pastigac0r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:00",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959096": [
        {
            "ioc_value": "slot777gacors.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:12:00",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959089": [
        {
            "ioc_value": "slot777gac0rvip.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:59",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959090": [
        {
            "ioc_value": "slotprokamboja.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:59",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959091": [
        {
            "ioc_value": "spaceman1win.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:59",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959092": [
        {
            "ioc_value": "tangoeventlive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:59",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959085": [
        {
            "ioc_value": "soholat.sa",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:58",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959086": [
        {
            "ioc_value": "sprkljewelrystore.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:58",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959087": [
        {
            "ioc_value": "slickassist.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:58",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959088": [
        {
            "ioc_value": "spaceman1vip.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:58",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959084": [
        {
            "ioc_value": "secretcrush.fun",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:11:57",
            "last_seen_utc": "2026-10-09 21:02:49",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959083": [
        {
            "ioc_value": "82b123782487af3a71494100a6338c47484d6c87e8531f6b9a801ad586cdf2df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959082": [
        {
            "ioc_value": "9ee6df848b98a0814c42a3cbc83779b5617ec4fbef0c3d89848df8bb787312cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:50",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959081": [
        {
            "ioc_value": "32d0ef1342989d373e942d3676ab127942e354a5a7db17c925eb2790c25405e8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-09 20:10:49",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Bashlite,cowrie,elf,Gafgyt,honeypot,i386,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959080": [
        {
            "ioc_value": "826a5ee2424545c2018f4c61f370f77bac6668a853c4d6c1168b337d3e195b6b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959079": [
        {
            "ioc_value": "a3a8051a4eb4b62dfcedea6eefb2466ec678e466c14d0e312852c87972d241ef",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959078": [
        {
            "ioc_value": "cdb6022fead9c73df39efb0898757fa55e996133606f44491255d0b153a99cf8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959077": [
        {
            "ioc_value": "9c9b5c83106040ac93b44e279c4441ba216632bc4cec64d105bc1170a72c2a21",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959076": [
        {
            "ioc_value": "384929a929d88aebae9e56ff8256bc5fc97be715b50cb942bbad277d9cfe355e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959075": [
        {
            "ioc_value": "afca6553105ea31dc41d19fd348e8ddef6203512d2d40c4c13d78b9fbe0e1379",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:43",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959074": [
        {
            "ioc_value": "05fd5edfb93a217b8ca710d6a5e6112bfef597fdbe95ec72860b682c35c5847a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:42",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959073": [
        {
            "ioc_value": "87108412822b2038b357b2f3a217bf3364f775b592236631c9d2e4783ad99b80",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959072": [
        {
            "ioc_value": "d86d75654b687dd05729185f7e41cd756e9836ca7bd89e4a36758f61eef01c8c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:40",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959071": [
        {
            "ioc_value": "d7edcb3e2a8784848f01d9b43e9755cbbf12399d6ea31157bc1a2a5d70cab1b7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959070": [
        {
            "ioc_value": "da29e92420d940f256d58a8a2d1db13b2c549ad7fa48e6c748d5e5fbb08cc9eb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959069": [
        {
            "ioc_value": "9915fb507f61981bfe73c56997fb6c3c3251e50926fb8ca44b24cb61e054c8df",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959068": [
        {
            "ioc_value": "3719af53c72cac4671b20a24eca975fce25bfa7c2ea48bc8afac7177a8d65fe1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959067": [
        {
            "ioc_value": "f8539675d9701f6aeb5d7630ed1d3fc86172399fb0f414c9f5788c412ba193c5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:35",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959066": [
        {
            "ioc_value": "55d19b5c675819d5d2492e10bd44028d3e02426c7fa486c4515b804943e8d54e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:34",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959065": [
        {
            "ioc_value": "dc6877cec9ef8cc706929bb0edbac4de2c45ee5cfe869308f027801f84fa9852",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:33",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959064": [
        {
            "ioc_value": "37ba5193546b50fe67376a8be6dbe4336a1b8175325d537fe0890576230cdc8f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:32",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959063": [
        {
            "ioc_value": "9c2ef4818f9ac03d14212e5429fa861facb61abd0e19423b1acc532270491240",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:31",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959062": [
        {
            "ioc_value": "1fb799ef7061df38c45a23ceac84cdd4c9595ba2be70226fd5e040d6a978d4fa",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.bashlite",
            "malware_alias": "gayfgt,Gafgyt,qbot,torlus,lizkebab",
            "malware_printable": "Bashlite",
            "first_seen_utc": "2026-10-09 20:10:30",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "Bashlite,sh",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959061": [
        {
            "ioc_value": "a56c709e47179c826ada4e91c7d24c0e9f2d020ad756c36d19d43fe0d9333cad",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-09 20:10:29",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "AgentTesla,ps1",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959060": [
        {
            "ioc_value": "6c196428e65a6fe1939db93080871823d3004842fadd033149fede736e8b376c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 20:10:28",
            "last_seen_utc": null,
            "confidence_level": 85,
            "is_compromised": false,
            "reference": null,
            "tags": "Formbook,ps1",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959059": [
        {
            "ioc_value": "92c4bb40657fc462b226f34b4f65b6c9c89e10862c8ce14068879e8e80efbf47",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 20:10:27",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,js,RAT,vbs",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959058": [
        {
            "ioc_value": "6b4b3724c21b93a773823853c561d4da1b2d216879f30d40c20965cbef66f50e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:26",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959057": [
        {
            "ioc_value": "d54e450bcf0392d61af498d83b11271208049ee7679ab2576b7874cbad6bd43f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959056": [
        {
            "ioc_value": "870d8065347e60122d782496b9ba1880ea7826ad86febcc3b19e056f1da894c3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-10-09 20:10:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "579cd0,dropped-by-Amadey,exe,Stealc",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959055": [
        {
            "ioc_value": "57234a9b103f3637891e9c54a5b78c04bcc56092b05db7418b4bb433be4dd11e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959054": [
        {
            "ioc_value": "6188fff75bb18c6d61df6b9378542de07cbe01da1c162a5cc6ab6c5130b84457",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:21",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959053": [
        {
            "ioc_value": "00499f1a9eee6704252b483a4172495396bec2c56cc78787da99a38dd2548e9a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959052": [
        {
            "ioc_value": "fd7c203ba560eeb58110ec08907b665a43b2ec58f25db4d656ef32e6afb58e0d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959051": [
        {
            "ioc_value": "d6bac5a15715c7e1f917c1e9bda5631e852f0e61388efbbace90b5a00b653ad3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:18",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959050": [
        {
            "ioc_value": "bb85d7ed379fee306fa43fb0724720e5584bbcc6792780889408daf6f4024604",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:17",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959049": [
        {
            "ioc_value": "9fac6abd1c35da9e68fb4f00f33de82306adf96093ea806f3c42d4a153e39c9e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:16",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959048": [
        {
            "ioc_value": "df00f0dd7e94d5b0fa9bab04f681f313e8f7de19b8af9eca5e862290e1f7d519",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959047": [
        {
            "ioc_value": "f0cd29fff42a7dad4b00c7b1c684a7e759a159baef96f57a285e1ff7f61bbab5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:14",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959046": [
        {
            "ioc_value": "4dcfaccade6044355f8b933ad74c97085497d7e34762e5eab473dd2b5804b486",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959045": [
        {
            "ioc_value": "ceb3064b2db7948711964dbfaba861aee73ef415a4454929528b3f26a8dda263",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959044": [
        {
            "ioc_value": "7a0efc7fd55dd9e665342b788b092f5660597ba1e3526f1bec3be14399a06e53",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959043": [
        {
            "ioc_value": "311d843746a0c17469003556ee0fcce655f97ff20a304a3d6cf2c800dae44e50",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 20:10:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959042": [
        {
            "ioc_value": "c7dbec8d4b58e10355ccb773d5d859b0297ce55bd47a100eb9a117d531c3a2e3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 20:10:08",
            "last_seen_utc": "2026-10-10 21:09:11",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "exe,upx,Vidar",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1959039": [
        {
            "ioc_value": "156.67.105.187:5602",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 20:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959040": [
        {
            "ioc_value": "156.67.105.187:6060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 20:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959041": [
        {
            "ioc_value": "45.194.37.207:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-09 20:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959038": [
        {
            "ioc_value": "156.67.105.187:3210",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 20:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959037": [
        {
            "ioc_value": "156.67.105.187:3081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 20:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958971": [
        {
            "ioc_value": "https://tribot.co.uk/Tribot.jar",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 20:03:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1959032": [
        {
            "ioc_value": "supersoniczpay.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:56",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959033": [
        {
            "ioc_value": "spine-core.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:56",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959034": [
        {
            "ioc_value": "starvibecentral.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:56",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959035": [
        {
            "ioc_value": "softsalehub.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:56",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959036": [
        {
            "ioc_value": "simpsid.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:56",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959028": [
        {
            "ioc_value": "servalspeedandpower.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:55",
            "last_seen_utc": "2026-10-09 21:02:49",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959029": [
        {
            "ioc_value": "shreekantdaga.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:55",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959030": [
        {
            "ioc_value": "sober.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:55",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959031": [
        {
            "ioc_value": "solaristrategy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:55",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959024": [
        {
            "ioc_value": "spacemanwahx5k.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:54",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959025": [
        {
            "ioc_value": "taborla.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:54",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959026": [
        {
            "ioc_value": "spaceman1jepe.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:54",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959027": [
        {
            "ioc_value": "slot777gac0rwin.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 20:01:54",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1959023": [
        {
            "ioc_value": "https://sitecctv.com.au/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 20:00:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/sitecctv.com.au",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959021": [
        {
            "ioc_value": "https://soholat.sa/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 20:00:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/soholat.sa",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959022": [
        {
            "ioc_value": "https://rmfx.limited/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 20:00:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/rmfx.limited",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1959020": [
        {
            "ioc_value": "pinkkate.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 19:55:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959019": [
        {
            "ioc_value": "qopamyfi.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 19:54:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1959018": [
        {
            "ioc_value": "94.158.187.147:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:48",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959017": [
        {
            "ioc_value": "84.237.141.86:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:45:38",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959014": [
        {
            "ioc_value": "77.67.125.218:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959015": [
        {
            "ioc_value": "77.67.125.219:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959016": [
        {
            "ioc_value": "77.67.125.220:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959010": [
        {
            "ioc_value": "68.166.230.138:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959011": [
        {
            "ioc_value": "68.166.230.139:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959012": [
        {
            "ioc_value": "68.166.230.224:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959013": [
        {
            "ioc_value": "68.166.230.225:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959009": [
        {
            "ioc_value": "68.166.230.137:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:30",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959008": [
        {
            "ioc_value": "66.179.208.104:2244",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:45:29",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959007": [
        {
            "ioc_value": "46.246.6.18:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:45:20",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959006": [
        {
            "ioc_value": "45.88.91.164:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:45:17",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959003": [
        {
            "ioc_value": "45.195.150.223:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:15",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959004": [
        {
            "ioc_value": "45.195.150.224:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:15",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959005": [
        {
            "ioc_value": "45.195.150.64:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:15",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959002": [
        {
            "ioc_value": "45.195.150.194:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:45:14",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959001": [
        {
            "ioc_value": "45.139.104.26:56015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:45:11",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1959000": [
        {
            "ioc_value": "41.234.38.191:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:45:07",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958999": [
        {
            "ioc_value": "217.60.77.63:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:44:49",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958997": [
        {
            "ioc_value": "217.60.102.74:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:44:46",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958998": [
        {
            "ioc_value": "217.60.195.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:44:46",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958996": [
        {
            "ioc_value": "xobyqo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 19:44:37",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958995": [
        {
            "ioc_value": "2.50.131.185:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:44:19",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958993": [
        {
            "ioc_value": "194.59.31.175:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958994": [
        {
            "ioc_value": "194.59.31.175:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958992": [
        {
            "ioc_value": "192.120.42.96:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:44:09",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958991": [
        {
            "ioc_value": "192.120.42.95:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:44:08",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958990": [
        {
            "ioc_value": "178.16.52.239:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 19:43:57",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958989": [
        {
            "ioc_value": "173.214.167.250:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:43:55",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958988": [
        {
            "ioc_value": "172.111.139.12:3002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-09 19:43:52",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958985": [
        {
            "ioc_value": "157.66.49.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:43:44",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958986": [
        {
            "ioc_value": "157.66.49.106:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:43:44",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958987": [
        {
            "ioc_value": "157.66.49.106:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:43:44",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958984": [
        {
            "ioc_value": "157.20.182.15:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:43:43",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958980": [
        {
            "ioc_value": "156.252.120.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958981": [
        {
            "ioc_value": "156.252.79.221:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958982": [
        {
            "ioc_value": "156.252.79.223:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958983": [
        {
            "ioc_value": "156.252.79.99:25204",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958979": [
        {
            "ioc_value": "154.86.8.239:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:40",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958978": [
        {
            "ioc_value": "138.124.91.187:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 19:43:27",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958976": [
        {
            "ioc_value": "128.1.120.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:19",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958977": [
        {
            "ioc_value": "128.1.121.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-09 19:43:19",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958975": [
        {
            "ioc_value": "117.55.235.249:30001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 19:43:17",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958974": [
        {
            "ioc_value": "104.254.90.122:36516",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:43:13",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958973": [
        {
            "ioc_value": "103.215.216.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-10-09 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958972": [
        {
            "ioc_value": "102.117.164.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958970": [
        {
            "ioc_value": "google-proxy-66-249-88-231.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 19:34:20",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958935": [
        {
            "ioc_value": "https://77.42.10.33",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 19:32:50",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "963c380fb63052aa256c33180f42398b,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958960": [
        {
            "ioc_value": "https://OSMB.net/OSMB.jar",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 19:32:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1958961": [
        {
            "ioc_value": "https://OSBOT.net/OSBot.jar",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 19:32:48",
            "last_seen_utc": "2026-10-09 21:09:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1958962": [
        {
            "ioc_value": "https://stellaspicy.org/2026scrill/RuneLite.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 19:32:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1958963": [
        {
            "ioc_value": "https://stellaspicy.org/2026scrill/client.jar",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 19:32:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1958964": [
        {
            "ioc_value": "https://stellaspicy.org/2026scrill/ping.php",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 19:32:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1958965": [
        {
            "ioc_value": "https://stellaspicy.org/2026scrill/webhook.php",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 19:32:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ratcatchers"
        }
    ],
    "1958966": [
        {
            "ioc_value": "professorpaulomoraes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 19:32:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://www.clickfixed.uk/intel/19378",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "ClickFixer"
        }
    ],
    "1958967": [
        {
            "ioc_value": "b4dff4250beca65d3a60492ca16eb82775c2014e8dd47c45d3c4a12a179ce911",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 19:32:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1958968": [
        {
            "ioc_value": "412efee735a28583cbfde94d141b0296",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 19:32:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "runelure,stealer,trojan",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1958969": [
        {
            "ioc_value": "55e1fc4352dffdf9954e90a162b23fa9744dfef6d9e058e6bd04b356decac73d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:32:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/55e1fc4352dffdf9954e90a162b23fa9744dfef6d9e058e6bd04b356decac73d",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958959": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561198628246386",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 19:15:35",
            "last_seen_utc": "2026-10-10 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c7dbec8d4b58e10355ccb773d5d859b0297ce55bd47a100eb9a117d531c3a2e3/",
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958958": [
        {
            "ioc_value": "https://telegram.me/scii0n",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 19:15:34",
            "last_seen_utc": "2026-10-10 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c7dbec8d4b58e10355ccb773d5d859b0297ce55bd47a100eb9a117d531c3a2e3/",
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958954": [
        {
            "ioc_value": "http://142.93.131.83/api/metrics/run",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:15:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AMOS,AtomicStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958955": [
        {
            "ioc_value": "http://142.93.131.83/contact",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:15:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AMOS,AtomicStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958956": [
        {
            "ioc_value": "http://165.232.88.231/api/metrics/run",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:15:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AMOS,AtomicStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958957": [
        {
            "ioc_value": "http://165.232.88.231/contact",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:15:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AMOS,AtomicStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958952": [
        {
            "ioc_value": "http://152.42.143.45/api/metrics/run",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:15:15",
            "last_seen_utc": "2026-10-09 19:15:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AMOS,AtomicStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958953": [
        {
            "ioc_value": "http://152.42.143.45/contact",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 19:15:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "AMOS,AtomicStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958951": [
        {
            "ioc_value": "56.242.95.34.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 19:12:06",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958950": [
        {
            "ioc_value": "7050da3bd5b59468f4ab8457cf5f11b1cd5f556e54e2e0b1d5b1556088b949d8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:06:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958949": [
        {
            "ioc_value": "774804269c551c1bca7c2ddebd28e63804e8b7e6c10b17241ef540e1718df6bf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:06:03",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958948": [
        {
            "ioc_value": "a50bfa26d8fa0c64bc8524aa0b152d01000d65de50b81de34489483e1280b632",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:06:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958947": [
        {
            "ioc_value": "a4e54b021c69560422159eb4cdf54a27c92ef4feafb5516b4c9976d23d1c088a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:06:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958946": [
        {
            "ioc_value": "e9dbeca946ed1f037ea1c14ce8df09b635ce876c22cd4c1c8aaaed3bda085eee",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 19:06:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,exe,upx",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958945": [
        {
            "ioc_value": "b74cb10109cbd5d8dbfb3d2b34016991f69430fb9fc6553ddf7371a0e189c2ae",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:05:58",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958944": [
        {
            "ioc_value": "a1bca91d3e2bd012c3e0dbe88e09062848c1cff602c990a541d7b1c9224ad16e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:05:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958943": [
        {
            "ioc_value": "8008767e83e3baa563ee9880881518dde6b43ae99f8c5585c05d61936f9d01dd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 19:05:56",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958942": [
        {
            "ioc_value": "https://docyard.live/downloads/docyard-windows-beta.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 19:05:48",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,RustyStealer,stealer",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958941": [
        {
            "ioc_value": "https://ed75a310.infinityindians.pages.dev/ktool.exe",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-09 19:05:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,Havoc",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958939": [
        {
            "ioc_value": "156.67.105.187:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 19:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958940": [
        {
            "ioc_value": "156.67.105.187:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 19:05:09",
            "last_seen_utc": "2026-10-11 08:17:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958938": [
        {
            "ioc_value": "156.67.105.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 19:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958936": [
        {
            "ioc_value": "120.76.143.184:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958937": [
        {
            "ioc_value": "156.67.105.187:3013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 19:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958934": [
        {
            "ioc_value": "vofaca.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 18:59:02",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958933": [
        {
            "ioc_value": "178.16.53.15:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-09 18:52:38",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "XWorm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958932": [
        {
            "ioc_value": "152.232.62.56:3609",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "jar.strrat",
            "malware_alias": null,
            "malware_printable": "STRRAT",
            "first_seen_utc": "2026-10-09 18:48:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5545db985bc48f969e40e3487215038b9c04de2f5e5ba3126e28cea0948a7ec1/",
            "tags": "RAT,STRRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958930": [
        {
            "ioc_value": "www.testmipagina.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958931": [
        {
            "ioc_value": "mavisuru.lk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:46",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958929": [
        {
            "ioc_value": "www.yomepreparo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:45",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958926": [
        {
            "ioc_value": "maxwin888jp.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:44",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958927": [
        {
            "ioc_value": "maldivescasinoguides.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:44",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958928": [
        {
            "ioc_value": "www.vansbeauty.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958922": [
        {
            "ioc_value": "mahjongways4.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:43",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958923": [
        {
            "ioc_value": "mahjongwin888.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:43",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958924": [
        {
            "ioc_value": "mahjong11jepe.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:43",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958925": [
        {
            "ioc_value": "max-eon4sl.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:43",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958918": [
        {
            "ioc_value": "maxwinquez.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:42",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958919": [
        {
            "ioc_value": "manuscriptrevision.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:42",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958920": [
        {
            "ioc_value": "mahjongwin777.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:42",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958921": [
        {
            "ioc_value": "mahkota218win.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:42",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958917": [
        {
            "ioc_value": "www.medinmoc.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:46:41",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958916": [
        {
            "ioc_value": "150.40.98.200:4521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.lxbaserat",
            "malware_alias": null,
            "malware_printable": "LxBase RAT",
            "first_seen_utc": "2026-10-09 18:42:25",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/47d55b8f04c66c808fdeda600a163f721a97df25011f7d4967593e8db021f06e/",
            "tags": "LxBaseRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958914": [
        {
            "ioc_value": "lilyknowsdecor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:36",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958915": [
        {
            "ioc_value": "jeh.org.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:36",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958910": [
        {
            "ioc_value": "machinelearninggeek.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:35",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958911": [
        {
            "ioc_value": "lifenote.com.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:35",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958912": [
        {
            "ioc_value": "labpbn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:35",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958913": [
        {
            "ioc_value": "laksanaberita.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:35",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958907": [
        {
            "ioc_value": "langdalemanornainital.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:34",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958908": [
        {
            "ioc_value": "kaidocafe.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:34",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958909": [
        {
            "ioc_value": "lamsanaqaa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:34",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958903": [
        {
            "ioc_value": "ketanhitam.my.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:33",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958904": [
        {
            "ioc_value": "ligamajestic.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:33",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958905": [
        {
            "ioc_value": "ladieluminous.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:33",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958906": [
        {
            "ioc_value": "leesalives.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:33",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958900": [
        {
            "ioc_value": "kochherzrezepte.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:32",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958901": [
        {
            "ioc_value": "medicalschoolcompanion.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:32",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958902": [
        {
            "ioc_value": "maslife.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:32",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958899": [
        {
            "ioc_value": "letsgetlyrical.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:36:31",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958898": [
        {
            "ioc_value": "mawos.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:32:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1958350": [
        {
            "ioc_value": "9729fa84525e187adcd325a7ac8bb9115a8c9242b434ec5d1e8d3c08c5ade004",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 18:29:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/9729fa84525e187adcd325a7ac8bb9115a8c9242b434ec5d1e8d3c08c5ade004",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958367": [
        {
            "ioc_value": "38.247.148.179:1020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 18:29:44",
            "last_seen_utc": "2026-10-11 08:02:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958397": [
        {
            "ioc_value": "128.90.106.110:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 18:29:43",
            "last_seen_utc": "2026-10-09 20:38:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Star-Baby-27",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958618": [
        {
            "ioc_value": "https://212.147.244.162",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 18:29:43",
            "last_seen_utc": "2026-10-09 20:53:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,eeab4ba1e04ed4eed509ec418cbe5d87,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958619": [
        {
            "ioc_value": "https://nr.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 18:29:43",
            "last_seen_utc": "2026-10-11 07:28:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "18094918b35ccec7caaf0b129e6d0490,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958626": [
        {
            "ioc_value": "boouwer.lol",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-10-09 18:29:42",
            "last_seen_utc": "2026-10-11 09:09:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958823": [
        {
            "ioc_value": "veled.com.tr",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "jar.supremebot",
            "malware_alias": "BlazeBot",
            "malware_printable": "SupremeBot",
            "first_seen_utc": "2026-10-09 18:29:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "noface,Supreme",
            "anonymous": 0,
            "reporter": "nullgrep"
        }
    ],
    "1958824": [
        {
            "ioc_value": "108.165.233.147:1339",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "jar.supremebot",
            "malware_alias": "BlazeBot",
            "malware_printable": "SupremeBot",
            "first_seen_utc": "2026-10-09 18:29:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "noface,Supreme",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958825": [
        {
            "ioc_value": "http://veled.com.tr/api/webhooks/bf275c79b814f8c5/g-aSnkfbqsjQs_HiPlDNR-9FRJC0sdc-",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "jar.supremebot",
            "malware_alias": "BlazeBot",
            "malware_printable": "SupremeBot",
            "first_seen_utc": "2026-10-09 18:29:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "noface,Supreme",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958869": [
        {
            "ioc_value": "https://ai.myrtlelexicon.co/auth/dashboard-cache",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-10-09 18:29:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958870": [
        {
            "ioc_value": "ai.myrtlelexicon.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-10-09 18:29:37",
            "last_seen_utc": "2026-10-09 18:13:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958871": [
        {
            "ioc_value": "https://ai.myrtlelexicon.co/auth/permission-render.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-10-09 18:29:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958895": [
        {
            "ioc_value": "a3ffd6fb5dc5f9d720858ca67e33a2cf26fe04d62bbc3e42d24b418fb75afa0f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 18:29:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/a3ffd6fb5dc5f9d720858ca67e33a2cf26fe04d62bbc3e42d24b418fb75afa0f",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958897": [
        {
            "ioc_value": "bed.camp-cantina.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:29:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1958896": [
        {
            "ioc_value": "bed.camp-cantina.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 18:28:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1958891": [
        {
            "ioc_value": "kwggame.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:30",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958892": [
        {
            "ioc_value": "laurexis.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:30",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958893": [
        {
            "ioc_value": "magicalminds.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:30",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958894": [
        {
            "ioc_value": "janapriya.ventures",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:30",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958888": [
        {
            "ioc_value": "lighthouse.com.tr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:29",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958889": [
        {
            "ioc_value": "koppelmaxim.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:29",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958890": [
        {
            "ioc_value": "jackmccallum.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:29",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958884": [
        {
            "ioc_value": "luluni.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:28",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958885": [
        {
            "ioc_value": "magnariseai.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:28",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958886": [
        {
            "ioc_value": "layanan.link",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:28",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958887": [
        {
            "ioc_value": "kcaraipur.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:28",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958880": [
        {
            "ioc_value": "joker123dragon.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:27",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958881": [
        {
            "ioc_value": "lapantaleteria.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:27",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958882": [
        {
            "ioc_value": "komaniboattour.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:27",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958883": [
        {
            "ioc_value": "kkeagle.food",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:27",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958876": [
        {
            "ioc_value": "jakartaequestrian.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:26",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958877": [
        {
            "ioc_value": "luckyspin-gozo78.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:26",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958878": [
        {
            "ioc_value": "jpslot100.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:26",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958879": [
        {
            "ioc_value": "kingresproperties.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:26",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958875": [
        {
            "ioc_value": "lensaberita.biz.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:21:25",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958874": [
        {
            "ioc_value": "http://103.196.161.244:43459/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-09 18:19:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.196.161.244",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1958872": [
        {
            "ioc_value": "http://arqtsop.shop:9932/documents",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-09 18:17:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1958873": [
        {
            "ioc_value": "http://trwehop.shop:5627/comments",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-09 18:17:03",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1958868": [
        {
            "ioc_value": "inlife.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:11:24",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958867": [
        {
            "ioc_value": "lumenshiftapp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:11:23",
            "last_seen_utc": "2026-10-09 21:02:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958866": [
        {
            "ioc_value": "hramsvetogapostolapavla.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:23",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958864": [
        {
            "ioc_value": "www.inkanuna.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958865": [
        {
            "ioc_value": "www.pennmedicaltrans.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958863": [
        {
            "ioc_value": "houzzim.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:21",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958862": [
        {
            "ioc_value": "www.minervatics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958858": [
        {
            "ioc_value": "innovanceorbit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:19",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958859": [
        {
            "ioc_value": "icte-dubai.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:19",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958860": [
        {
            "ioc_value": "www.ioss.si",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958861": [
        {
            "ioc_value": "hotela.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 18:01:19",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958857": [
        {
            "ioc_value": "https://sanxuatmay.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 18:01:00",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/sanxuatmay.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958854": [
        {
            "ioc_value": "https://komaniboattour.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 18:00:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/komaniboattour.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958855": [
        {
            "ioc_value": "https://kaidocafe.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 18:00:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/kaidocafe.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958856": [
        {
            "ioc_value": "https://laurexis.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 18:00:59",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/laurexis.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958853": [
        {
            "ioc_value": "2a02-1811-a407-5e00-8864-e91f-e22d-840c.ip6.access.telenet.be",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 17:57:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958852": [
        {
            "ioc_value": "huffington-post.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:16",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958849": [
        {
            "ioc_value": "ithracars.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:15",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958850": [
        {
            "ioc_value": "honeytech.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:15",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958851": [
        {
            "ioc_value": "inkfold-ext.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:15",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958845": [
        {
            "ioc_value": "inventixdigital.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:14",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958846": [
        {
            "ioc_value": "idnslot777.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:14",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958847": [
        {
            "ioc_value": "iids.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:14",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958848": [
        {
            "ioc_value": "ingpras.one",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:14",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958844": [
        {
            "ioc_value": "huynhieu.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:51:13",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958843": [
        {
            "ioc_value": "213.218.95.34.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 17:48:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958842": [
        {
            "ioc_value": "143.21.187.35.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 17:46:23",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958841": [
        {
            "ioc_value": "4bgr76dk.morib.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:44:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958840": [
        {
            "ioc_value": "eikonsolucoes.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:12",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958836": [
        {
            "ioc_value": "gmtn.net.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:11",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958837": [
        {
            "ioc_value": "gypsysouldreaming.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:11",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958838": [
        {
            "ioc_value": "esaenergy.com.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:11",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958839": [
        {
            "ioc_value": "hmsbd.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:11",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958832": [
        {
            "ioc_value": "email938.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:10",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958833": [
        {
            "ioc_value": "ganpatimovers.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:10",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958834": [
        {
            "ioc_value": "ezlyfebd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:10",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958835": [
        {
            "ioc_value": "fixteethtmj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:10",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958830": [
        {
            "ioc_value": "esdev.my.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:09",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958831": [
        {
            "ioc_value": "healthyyou.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:09",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958827": [
        {
            "ioc_value": "explainedendings.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:08",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958828": [
        {
            "ioc_value": "garrikwolfe.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:08",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958829": [
        {
            "ioc_value": "fitwin.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:41:08",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958826": [
        {
            "ioc_value": "26.146.187.35.bc.googleusercontent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 17:38:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958822": [
        {
            "ioc_value": "fire-iptv.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:54",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958817": [
        {
            "ioc_value": "esseguro.net.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:53",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958818": [
        {
            "ioc_value": "eombridge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:53",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958819": [
        {
            "ioc_value": "guleryuzmucevherat.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:53",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958820": [
        {
            "ioc_value": "gjhome.ovh",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:53",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958821": [
        {
            "ioc_value": "glitsychic.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:53",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958813": [
        {
            "ioc_value": "elbaaz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:52",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958814": [
        {
            "ioc_value": "escapejourney.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:52",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958815": [
        {
            "ioc_value": "emplopedia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:52",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958816": [
        {
            "ioc_value": "harvestingcontemplations.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:52",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958809": [
        {
            "ioc_value": "eurototop1win.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:51",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958810": [
        {
            "ioc_value": "footbulz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:51",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958811": [
        {
            "ioc_value": "ethicaltone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:51",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958812": [
        {
            "ioc_value": "emass.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:51",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958805": [
        {
            "ioc_value": "gacor2025.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:50",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958806": [
        {
            "ioc_value": "ekayzone.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:50",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958807": [
        {
            "ioc_value": "econuco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:50",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958808": [
        {
            "ioc_value": "ernest.my.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:50",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958802": [
        {
            "ioc_value": "highesthzmonitor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:49",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958803": [
        {
            "ioc_value": "gacor2025win.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:49",
            "last_seen_utc": "2026-10-09 21:02:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958804": [
        {
            "ioc_value": "elitepool.lk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:49",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958800": [
        {
            "ioc_value": "emss.co.th",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:48",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958801": [
        {
            "ioc_value": "fifaworldcup-2026.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:30:48",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958798": [
        {
            "ioc_value": "https://xt.33pedia.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 17:28:52",
            "last_seen_utc": "2026-10-11 07:30:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1958799": [
        {
            "ioc_value": "https://xt.4toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 17:28:52",
            "last_seen_utc": "2026-10-11 07:32:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1958797": [
        {
            "ioc_value": "uptight5912.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 17:24:58",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958796": [
        {
            "ioc_value": "1lpwxzik.lunza.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 17:21:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958793": [
        {
            "ioc_value": "www.construccionescrisvi.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:20:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958794": [
        {
            "ioc_value": "desalagilisejahtera.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:20:47",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958795": [
        {
            "ioc_value": "cartec.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:20:47",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958791": [
        {
            "ioc_value": "contenidoneto.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:20:46",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958792": [
        {
            "ioc_value": "www.brightmarkconsultingltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:20:46",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958790": [
        {
            "ioc_value": "d-oneelectrical.com.my",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:20:45",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958789": [
        {
            "ioc_value": "lalaxafe.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 17:19:48",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958788": [
        {
            "ioc_value": "tka9o28q.renad.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:15:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958784": [
        {
            "ioc_value": "whisperingheavens.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:45",
            "last_seen_utc": "2026-10-09 18:46:46",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958785": [
        {
            "ioc_value": "xn--42cga1id4d9c7co1e.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:45",
            "last_seen_utc": "2026-10-09 18:46:46",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958786": [
        {
            "ioc_value": "xn--rotulosydiseo-tkb.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958787": [
        {
            "ioc_value": "zainyapparels.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:45",
            "last_seen_utc": "2026-10-09 18:46:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958774": [
        {
            "ioc_value": "szklarka.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": "2026-10-09 18:56:48",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958775": [
        {
            "ioc_value": "tattonhallhomes.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": "2026-10-09 18:36:35",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958776": [
        {
            "ioc_value": "techcom.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958777": [
        {
            "ioc_value": "testmipagina.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958778": [
        {
            "ioc_value": "tezanholidays.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": "2026-10-09 19:16:50",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958779": [
        {
            "ioc_value": "tothgeorgina.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": "2026-10-09 18:46:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958780": [
        {
            "ioc_value": "ultrasound-probe-repair.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": "2026-10-09 18:46:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958781": [
        {
            "ioc_value": "unodeagosto.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958782": [
        {
            "ioc_value": "valdai-1.ru",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": "2026-10-09 18:46:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958783": [
        {
            "ioc_value": "vansbeauty.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958765": [
        {
            "ioc_value": "riderbagsbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 17:51:16",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958766": [
        {
            "ioc_value": "rinogropuzzo.hr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 17:51:17",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958767": [
        {
            "ioc_value": "royalpacificbodegabay.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 17:51:16",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958768": [
        {
            "ioc_value": "ruaytep168a.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 18:11:24",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958769": [
        {
            "ioc_value": "schmutzbarth.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958770": [
        {
            "ioc_value": "sinux.com.ar",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 18:01:21",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958771": [
        {
            "ioc_value": "startne.works",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 17:51:15",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958772": [
        {
            "ioc_value": "stayshortlets.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 19:16:50",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958773": [
        {
            "ioc_value": "stonewellar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:43",
            "last_seen_utc": "2026-10-09 18:11:24",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958756": [
        {
            "ioc_value": "mdfs.co.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": "2026-10-09 18:01:21",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958757": [
        {
            "ioc_value": "minervatics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958758": [
        {
            "ioc_value": "mltecnologia.ar",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": "2026-10-09 18:01:20",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958759": [
        {
            "ioc_value": "naam.neagest.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": "2026-10-09 18:11:24",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958760": [
        {
            "ioc_value": "nationwidefleetservices.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": "2026-10-09 18:56:48",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958761": [
        {
            "ioc_value": "northtexascowboycleaners.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958762": [
        {
            "ioc_value": "pantingdeerpublishing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": "2026-10-09 17:51:17",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958763": [
        {
            "ioc_value": "pennmedicaltrans.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958764": [
        {
            "ioc_value": "product11solutions.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:42",
            "last_seen_utc": "2026-10-09 17:51:17",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958753": [
        {
            "ioc_value": "kyuta.my.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958754": [
        {
            "ioc_value": "maithiphuong.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:41",
            "last_seen_utc": "2026-10-09 18:01:20",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958755": [
        {
            "ioc_value": "markamigoni.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:41",
            "last_seen_utc": "2026-10-09 18:01:21",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958750": [
        {
            "ioc_value": "inkanuna.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958751": [
        {
            "ioc_value": "jesuseselrey.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:08",
            "last_seen_utc": "2026-10-09 17:51:17",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958752": [
        {
            "ioc_value": "kovidguptafilms.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:08",
            "last_seen_utc": "2026-10-09 18:01:19",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958743": [
        {
            "ioc_value": "farmware.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": "2026-10-09 17:41:12",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958744": [
        {
            "ioc_value": "finanja.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": "2026-10-09 18:56:47",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958745": [
        {
            "ioc_value": "first-frankfurt.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958746": [
        {
            "ioc_value": "foreignerbazaar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": "2026-10-09 17:41:12",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958747": [
        {
            "ioc_value": "gmbhsuppliers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": "2026-10-09 17:41:12",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958748": [
        {
            "ioc_value": "housobread.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": "2026-10-09 17:51:16",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958749": [
        {
            "ioc_value": "hyphagen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:07",
            "last_seen_utc": "2026-10-09 18:01:20",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958737": [
        {
            "ioc_value": "construccionescrisvi.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:06",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958738": [
        {
            "ioc_value": "current-installations.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:06",
            "last_seen_utc": "2026-10-09 17:20:46",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958739": [
        {
            "ioc_value": "des-aprendiendodigital.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:06",
            "last_seen_utc": "2026-10-09 18:46:47",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958740": [
        {
            "ioc_value": "digitalshorts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:06",
            "last_seen_utc": "2026-10-09 18:56:48",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958741": [
        {
            "ioc_value": "dmunc.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:06",
            "last_seen_utc": "2026-10-09 18:56:48",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958742": [
        {
            "ioc_value": "encuentro991.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:06",
            "last_seen_utc": "2026-10-09 19:06:49",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958736": [
        {
            "ioc_value": "adamconsultings.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-09 17:11:05",
            "last_seen_utc": "2026-10-09 18:46:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958735": [
        {
            "ioc_value": "165.245.252.125:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 17:09:27",
            "last_seen_utc": "2026-10-10 22:36:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958734": [
        {
            "ioc_value": "https://hp.3toto.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 17:05:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1958733": [
        {
            "ioc_value": "hp.3toto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 17:05:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1958731": [
        {
            "ioc_value": "circular-st.ru",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:30",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958732": [
        {
            "ioc_value": "cheapproxyservers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:30",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958728": [
        {
            "ioc_value": "concenpc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:29",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958729": [
        {
            "ioc_value": "christmasgiftideasforgirlfriends.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:29",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958730": [
        {
            "ioc_value": "conserveint.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:29",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958724": [
        {
            "ioc_value": "cvoc.imb.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:28",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958725": [
        {
            "ioc_value": "cursosonlinepremium.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:28",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958726": [
        {
            "ioc_value": "christiancordero.mba",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:28",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958727": [
        {
            "ioc_value": "c4soft.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:28",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958720": [
        {
            "ioc_value": "danatotowin888.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:27",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958721": [
        {
            "ioc_value": "cliput.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:27",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958722": [
        {
            "ioc_value": "deepakmehta.com.np",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:27",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958723": [
        {
            "ioc_value": "danatotalx1000.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:27",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958716": [
        {
            "ioc_value": "cybertalentit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:26",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958717": [
        {
            "ioc_value": "csaladiasztrologia.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:26",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958718": [
        {
            "ioc_value": "carolinelunara.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:26",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958719": [
        {
            "ioc_value": "demoslotmax1.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:26",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958712": [
        {
            "ioc_value": "coms.bd",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:25",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958713": [
        {
            "ioc_value": "concretepumpingauckland.co.nz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:25",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958714": [
        {
            "ioc_value": "cellexmedia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:25",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958715": [
        {
            "ioc_value": "demavaraes.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:25",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958709": [
        {
            "ioc_value": "conservesolution.ae",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:24",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958710": [
        {
            "ioc_value": "charge-point-cp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:24",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958711": [
        {
            "ioc_value": "dataset58.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:24",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958708": [
        {
            "ioc_value": "coffeeburnlab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 17:05:23",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958701": [
        {
            "ioc_value": "https://esaenergy.com.pk/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/esaenergy.com.pk",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958702": [
        {
            "ioc_value": "https://d-oneelectrical.com.my/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/d-oneelectrical.com.my",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958703": [
        {
            "ioc_value": "https://cursosonlinepremium.com.br/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/cursosonlinepremium.com.br",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958704": [
        {
            "ioc_value": "https://defiq.live/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/defiq.live",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958705": [
        {
            "ioc_value": "https://defiq.biz/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/defiq.biz",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958706": [
        {
            "ioc_value": "https://econuco.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/econuco.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958707": [
        {
            "ioc_value": "https://contenidoneto.click/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 17:00:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/contenidoneto.click",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958700": [
        {
            "ioc_value": "https://hp.333vip.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 17:00:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1958699": [
        {
            "ioc_value": "hp.333vip.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 17:00:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1958698": [
        {
            "ioc_value": "aailc.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:23",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958695": [
        {
            "ioc_value": "chipsrealm.fun",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:22",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958696": [
        {
            "ioc_value": "bytekboya.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:22",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958697": [
        {
            "ioc_value": "barnyard.pt",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:22",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958691": [
        {
            "ioc_value": "csdcbkp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:21",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958692": [
        {
            "ioc_value": "clip-stack.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:21",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958693": [
        {
            "ioc_value": "dampatya.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:21",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958694": [
        {
            "ioc_value": "decount.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:21",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958686": [
        {
            "ioc_value": "diceybrew.sbs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:20",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958687": [
        {
            "ioc_value": "depobosku777.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:20",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958688": [
        {
            "ioc_value": "demoslotgac0r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:20",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958689": [
        {
            "ioc_value": "demoslotgac1r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:20",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958690": [
        {
            "ioc_value": "depoboslotez1.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:20",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958683": [
        {
            "ioc_value": "africanyoutharchitects.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:19",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958684": [
        {
            "ioc_value": "defiq.biz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:19",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958685": [
        {
            "ioc_value": "defiq.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:55:19",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958681": [
        {
            "ioc_value": "biodiagnosticolab.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:18",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958682": [
        {
            "ioc_value": "britflix.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:18",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958677": [
        {
            "ioc_value": "authoritymarketingagent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:17",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958678": [
        {
            "ioc_value": "atwcolombia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:17",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958679": [
        {
            "ioc_value": "bambofashions.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:17",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958680": [
        {
            "ioc_value": "anphutaynguyen.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:17",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958673": [
        {
            "ioc_value": "bigwin800jp.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:16",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958674": [
        {
            "ioc_value": "bogem10.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:16",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958675": [
        {
            "ioc_value": "bonanza01gacors.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:16",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958676": [
        {
            "ioc_value": "bonanza1jepe.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:16",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958669": [
        {
            "ioc_value": "bongaentertainment.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:15",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958670": [
        {
            "ioc_value": "bonanza321gc0r.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:15",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958671": [
        {
            "ioc_value": "bonanzagac0r1.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:15",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958672": [
        {
            "ioc_value": "bolasbobet01st.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:15",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958665": [
        {
            "ioc_value": "bridgevita.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:14",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958666": [
        {
            "ioc_value": "bnappstech.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:14",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958667": [
        {
            "ioc_value": "bonanza123gac0r.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:14",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958668": [
        {
            "ioc_value": "brainsurface.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:14",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958664": [
        {
            "ioc_value": "blaszmogames.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:45:13",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958662": [
        {
            "ioc_value": "boardoria.sbs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:12",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958663": [
        {
            "ioc_value": "balazs-rwa.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:12",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958658": [
        {
            "ioc_value": "briefleaf.tech",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:11",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958659": [
        {
            "ioc_value": "bluejournals.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:11",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958660": [
        {
            "ioc_value": "bridgeimpex.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:11",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958661": [
        {
            "ioc_value": "bluebriefs.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:11",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958655": [
        {
            "ioc_value": "buscapreco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:10",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958656": [
        {
            "ioc_value": "bigsoftcare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:10",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958657": [
        {
            "ioc_value": "bluebrief.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:35:10",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958654": [
        {
            "ioc_value": "2i5dk6t5us.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 16:32:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958653": [
        {
            "ioc_value": "http://fafdafaf.shop/getinstall64",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 16:30:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,ValleyRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958651": [
        {
            "ioc_value": "www.basyoun.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:25:09",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958652": [
        {
            "ioc_value": "alshathri.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:25:09",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958647": [
        {
            "ioc_value": "botforextradx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:25:08",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958648": [
        {
            "ioc_value": "bluelogs.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:25:08",
            "last_seen_utc": "2026-10-09 21:02:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958649": [
        {
            "ioc_value": "battebare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:25:08",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958650": [
        {
            "ioc_value": "baiihua.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:25:08",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958641": [
        {
            "ioc_value": "sanbrosextrusionsmachines.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958642": [
        {
            "ioc_value": "scarunites.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958643": [
        {
            "ioc_value": "www.professorpaulomoraes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958644": [
        {
            "ioc_value": "www.rebatefirm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958645": [
        {
            "ioc_value": "www.uttaramahilapatrika.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958646": [
        {
            "ioc_value": "zamzamksa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:46",
            "last_seen_utc": "2026-10-09 19:27:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958638": [
        {
            "ioc_value": "joyous-holiday.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958639": [
        {
            "ioc_value": "movista.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958640": [
        {
            "ioc_value": "safestroutetransport.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958636": [
        {
            "ioc_value": "flutuarweb.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958637": [
        {
            "ioc_value": "gamschools.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:44",
            "last_seen_utc": "2026-10-09 19:19:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958635": [
        {
            "ioc_value": "aimst.org.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 16:19:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958634": [
        {
            "ioc_value": "bdggame.download",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:07",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958630": [
        {
            "ioc_value": "beatchronicles.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:06",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958631": [
        {
            "ioc_value": "beatcorner.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:06",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958632": [
        {
            "ioc_value": "angkasa138wons.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:06",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958633": [
        {
            "ioc_value": "aztec800jp.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:06",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958627": [
        {
            "ioc_value": "azurcode.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:05",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958628": [
        {
            "ioc_value": "batikllive22.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:05",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958629": [
        {
            "ioc_value": "baiifa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 16:15:05",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958625": [
        {
            "ioc_value": "globalcoclos.cc",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 16:09:48",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ZigClipper",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958620": [
        {
            "ioc_value": "https://bytekboya.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 16:00:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/bytekboya.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958621": [
        {
            "ioc_value": "https://alrehansign.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 16:00:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/alrehansign.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958622": [
        {
            "ioc_value": "https://bogem10.org/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 16:00:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/bogem10.org",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958623": [
        {
            "ioc_value": "https://cartec.in/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 16:00:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/cartec.in",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958624": [
        {
            "ioc_value": "https://christiancordero.mba/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 16:00:57",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/christiancordero.mba",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958617": [
        {
            "ioc_value": "ayohijab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:51",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958612": [
        {
            "ioc_value": "angkasato38jir.quest",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:50",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958613": [
        {
            "ioc_value": "angkasa138yabos.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:50",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958614": [
        {
            "ioc_value": "angkasatu38mmw.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:50",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958615": [
        {
            "ioc_value": "angkasatu38owe.quest",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:50",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958616": [
        {
            "ioc_value": "angkasatu38bos.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:50",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958608": [
        {
            "ioc_value": "angkasapurra.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:49",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958609": [
        {
            "ioc_value": "angkasapura2k.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:49",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958610": [
        {
            "ioc_value": "angkasa138yoks.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:49",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958611": [
        {
            "ioc_value": "asialive22.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:59:49",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958607": [
        {
            "ioc_value": "ayoorca.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:48",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958603": [
        {
            "ioc_value": "angkasapura2.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:47",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958604": [
        {
            "ioc_value": "angkasa138vvin.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:47",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958605": [
        {
            "ioc_value": "angkasa138wuw.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:47",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958606": [
        {
            "ioc_value": "asialivegac0r.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:47",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958599": [
        {
            "ioc_value": "askglobalbiz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:46",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958600": [
        {
            "ioc_value": "angkasa138win.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:46",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958601": [
        {
            "ioc_value": "avenyze.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:46",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958602": [
        {
            "ioc_value": "angkasa138wih.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:46",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958597": [
        {
            "ioc_value": "aniwave.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:45",
            "last_seen_utc": "2026-10-09 21:02:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958598": [
        {
            "ioc_value": "angkasa138w1n.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:49:45",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958594": [
        {
            "ioc_value": "1a9afbc2b7671c4b6b355da6da1572b1592aa9987396c332fa9bd2d07fca60e0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.burnbook",
            "malware_alias": null,
            "malware_printable": "BURNBOOK",
            "first_seen_utc": "2026-10-09 15:46:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958595": [
        {
            "ioc_value": "4bef79953a5c890139d817bec809cceacde97c22",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.burnbook",
            "malware_alias": null,
            "malware_printable": "BURNBOOK",
            "first_seen_utc": "2026-10-09 15:46:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958596": [
        {
            "ioc_value": "8e8b9b52536b4ec6b380201db4d3e898",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.burnbook",
            "malware_alias": null,
            "malware_printable": "BURNBOOK",
            "first_seen_utc": "2026-10-09 15:46:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958590": [
        {
            "ioc_value": "1d1965d1b99318c08a6272785aa4a90a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:46:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958591": [
        {
            "ioc_value": "a8a6f5ad5f6bc59b64af1cca3bf0d5b6bcc8686a0dd8a8bb5cb244c2edcf3e23",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:46:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958592": [
        {
            "ioc_value": "31b97fe2256c70164ad1661990f824bec502125f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:46:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958593": [
        {
            "ioc_value": "6367307dd5e1cbc6c1f0a160e0c5d421",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:46:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958588": [
        {
            "ioc_value": "570926ee424e877afad9ac8b18c2561b7931ad63affc951244da3c12380827b8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:46:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958589": [
        {
            "ioc_value": "f1ad2f39179ef1638acbdf4a6723d485c5655bb4",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:46:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958586": [
        {
            "ioc_value": "69f55a57d6353649c3f709163bb7d440a3a7eb7f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-10-09 15:46:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958587": [
        {
            "ioc_value": "b6ffc5ab3d9c3d132b0cdb490ed800d2",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-10-09 15:46:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958584": [
        {
            "ioc_value": "fdaaccb787847c17246cab70b759d47025a430fe",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958585": [
        {
            "ioc_value": "0bafb1133ee4dab935e4cedf0686fb1c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958581": [
        {
            "ioc_value": "13308ac704a70154856b5f75ec3d33bd628be888",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-10-09 15:45:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958582": [
        {
            "ioc_value": "156b6e957d1c8cfca30351e0b1bccd3a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-10-09 15:45:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958583": [
        {
            "ioc_value": "be65797d62ee77d94954f8fb367428f7c37f0a183f93c4a743a1ad9cfe393066",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958577": [
        {
            "ioc_value": "4f4129e8f79bde102875417f64a3258226ae93658776a416aaf4383698a6ea7d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.mispadu",
            "malware_alias": "URSA",
            "malware_printable": "Mispadu",
            "first_seen_utc": "2026-10-09 15:45:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958578": [
        {
            "ioc_value": "933d61b725414ff1ca8776ee4193aa0c1a77b107",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.mispadu",
            "malware_alias": "URSA",
            "malware_printable": "Mispadu",
            "first_seen_utc": "2026-10-09 15:45:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958579": [
        {
            "ioc_value": "97e42e50ecb6690f179b58c20f9de633",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.mispadu",
            "malware_alias": "URSA",
            "malware_printable": "Mispadu",
            "first_seen_utc": "2026-10-09 15:45:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958580": [
        {
            "ioc_value": "a1e52621549b26c9ea46fdb4da21e159d2332fb0887c56ee317648597e99df63",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-10-09 15:45:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958575": [
        {
            "ioc_value": "30e3cdc2d6accb4037e0d3078058d34654a4935e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-09 15:45:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958576": [
        {
            "ioc_value": "6e7fb5ed733aedc9943cc4eb2ce744f5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-09 15:45:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958571": [
        {
            "ioc_value": "0fdc64087cfc4c062a2198b63c9e0286",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:53",
            "last_seen_utc": "2026-10-10 21:10:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958572": [
        {
            "ioc_value": "b13b22c66cd105a2e5a10bbc9339bfa0e4f4cb1faa4cd2d0a7ae854948d2b1c5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.tinymet",
            "malware_alias": "TiniMet",
            "malware_printable": "TinyMet",
            "first_seen_utc": "2026-10-09 15:45:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958573": [
        {
            "ioc_value": "6366ed2fb4b981985e3ce4dd9729dce539abbc03",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.tinymet",
            "malware_alias": "TiniMet",
            "malware_printable": "TinyMet",
            "first_seen_utc": "2026-10-09 15:45:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958574": [
        {
            "ioc_value": "3277f4122adfda4fc1c5b817523b0be0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.tinymet",
            "malware_alias": "TiniMet",
            "malware_printable": "TinyMet",
            "first_seen_utc": "2026-10-09 15:45:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958568": [
        {
            "ioc_value": "183b06f7a82543a77dba6ef0fcc4d759",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-10-09 15:45:52",
            "last_seen_utc": "2026-10-10 21:10:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958569": [
        {
            "ioc_value": "deb70d1f124c4dad405e0dc2c57d642bb993df9b09d225a6f7ff128adb055625",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:52",
            "last_seen_utc": "2026-10-10 21:10:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958570": [
        {
            "ioc_value": "66f9f4a8b31baf77508b48e48aefbb389cd056f3",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:52",
            "last_seen_utc": "2026-10-10 21:10:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958565": [
        {
            "ioc_value": "7a8499e4221283aeb5a55750372169f5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-10-09 15:45:51",
            "last_seen_utc": "2026-10-10 21:10:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958566": [
        {
            "ioc_value": "6932f169761f4ba8fbb584c5dfaff2bbaa7a1108c4e0175afdf2acac6feeeacd",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-10-09 15:45:51",
            "last_seen_utc": "2026-10-10 21:10:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958567": [
        {
            "ioc_value": "81ccbbf7b978388071dee52384120ae4df4b2b84",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-10-09 15:45:51",
            "last_seen_utc": "2026-10-10 21:10:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958562": [
        {
            "ioc_value": "23d02815c2d88958feb4b314ab3c1b9c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 15:45:50",
            "last_seen_utc": "2026-10-10 21:10:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958563": [
        {
            "ioc_value": "c21557a9b8df651692f8a6241e488dcfba8faf2dce446c14f5854ba1fa04d7f4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-10-09 15:45:50",
            "last_seen_utc": "2026-10-10 21:10:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958564": [
        {
            "ioc_value": "d11077f623786e7e7913c6a942c0e44bb77ece39",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.luca_stealer",
            "malware_alias": null,
            "malware_printable": "Luca Stealer",
            "first_seen_utc": "2026-10-09 15:45:50",
            "last_seen_utc": "2026-10-10 21:10:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958558": [
        {
            "ioc_value": "0f772ab2d5e02b7aef59bd70dc438f56e36e01e9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:49",
            "last_seen_utc": "2026-10-10 21:10:00",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958559": [
        {
            "ioc_value": "0ab63fac1e124db0dbaea7d0c8d2d609",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:49",
            "last_seen_utc": "2026-10-10 21:10:00",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958560": [
        {
            "ioc_value": "1b95c2783b667ad5ffbd5b66afc367a92c314f507ba43789ec0bcda5a623a877",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 15:45:49",
            "last_seen_utc": "2026-10-10 21:10:00",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958561": [
        {
            "ioc_value": "dd0152236bf703e6c95cfc66c9d6a4d163abb67f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 15:45:49",
            "last_seen_utc": "2026-10-10 21:10:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958555": [
        {
            "ioc_value": "db743e8316d8ad925409c8806c5f256971752f18",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:48",
            "last_seen_utc": "2026-10-10 21:09:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958556": [
        {
            "ioc_value": "0f8db1428213838c9d104f5369835969",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:48",
            "last_seen_utc": "2026-10-10 21:09:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958557": [
        {
            "ioc_value": "b0915fda8b68cc59f8c722080d133e823e9ae49bb3ad82d1f4faca1f14325284",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:48",
            "last_seen_utc": "2026-10-10 21:10:00",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958552": [
        {
            "ioc_value": "f515654bd03bc3c0636ab9334cc98b14ea81a19c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-09 15:45:47",
            "last_seen_utc": "2026-10-10 21:09:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958553": [
        {
            "ioc_value": "ff398178642634364b05ae413091f831",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-09 15:45:47",
            "last_seen_utc": "2026-10-10 21:09:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958554": [
        {
            "ioc_value": "492ac6489b05326e2fc2939af9ca842cb4f20dd708a4891e22e52ec6d268fdf7",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:47",
            "last_seen_utc": "2026-10-10 21:09:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958548": [
        {
            "ioc_value": "1ed0a0d1ec52bd6ef0635b0aaa0eb44550bb8d03e67f1cd08eb041e3ba128c01",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 15:45:46",
            "last_seen_utc": "2026-10-10 21:09:57",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958549": [
        {
            "ioc_value": "0ec61ca7b9a28ec2eabcba081c7d913645068115",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 15:45:46",
            "last_seen_utc": "2026-10-10 21:09:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958550": [
        {
            "ioc_value": "798d6bd179c9aa369aa4bce084265ce0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 15:45:46",
            "last_seen_utc": "2026-10-10 21:09:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958551": [
        {
            "ioc_value": "1f8604584b410ae9b6037d2975d01093832d6b63d454c4b9f40c8f3d1c8b89d5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-10-09 15:45:46",
            "last_seen_utc": "2026-10-10 21:09:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958544": [
        {
            "ioc_value": "40fb3059353fda2a810e736ed8888ad5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:45",
            "last_seen_utc": "2026-10-10 21:09:56",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958545": [
        {
            "ioc_value": "ef41e4af8abb91a0c77f60005bd985ff554fe368593bb0b60d09a5fc9a54bd98",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:45",
            "last_seen_utc": "2026-10-10 21:09:57",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958546": [
        {
            "ioc_value": "0a8c1c0632b383564e056ac6ce279de9381bfe26",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:45",
            "last_seen_utc": "2026-10-10 21:09:57",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958547": [
        {
            "ioc_value": "9e848a4af00c33c6b7f6dbe7dc06ed35",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:45",
            "last_seen_utc": "2026-10-10 21:09:57",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958542": [
        {
            "ioc_value": "b1226cf111753eb82f329cb657104059ac96c8692853d83aa4a70d9b8c2bb312",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:44",
            "last_seen_utc": "2026-10-10 21:09:56",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958543": [
        {
            "ioc_value": "9272479dcddd3aa9a9c78b1d1accb06d273e379f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "jar.crossrat",
            "malware_alias": "Trupto",
            "malware_printable": "CrossRAT",
            "first_seen_utc": "2026-10-09 15:45:44",
            "last_seen_utc": "2026-10-10 21:09:56",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958538": [
        {
            "ioc_value": "37c9778f7921ff7183a392f4f69436bc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-10-09 15:45:43",
            "last_seen_utc": "2026-10-10 21:09:55",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958539": [
        {
            "ioc_value": "9cea830b56c14b2d9c77d46a155e365176d35996d53708bb79ee6e41d04e51f3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:43",
            "last_seen_utc": "2026-10-10 21:09:55",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958540": [
        {
            "ioc_value": "3c3ed126a801ac98102591738979ba57d8b88edd",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:43",
            "last_seen_utc": "2026-10-10 21:09:55",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958541": [
        {
            "ioc_value": "778c4377017e6d60c536e258e73057bd",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:43",
            "last_seen_utc": "2026-10-10 21:09:56",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958534": [
        {
            "ioc_value": "6f43660205e58145576cccfd2bf24906c7555d57",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "elf.kuiper",
            "malware_alias": null,
            "malware_printable": "Kuiper",
            "first_seen_utc": "2026-10-09 15:45:42",
            "last_seen_utc": "2026-10-10 21:09:54",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958535": [
        {
            "ioc_value": "ed38148aefd5d9d866d46220b57c10f8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "elf.kuiper",
            "malware_alias": null,
            "malware_printable": "Kuiper",
            "first_seen_utc": "2026-10-09 15:45:42",
            "last_seen_utc": "2026-10-10 21:09:54",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958536": [
        {
            "ioc_value": "29765d721119f190c11bb2d972dcc86fdf73405ea20bd642a8932efd3fa8d980",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-10-09 15:45:42",
            "last_seen_utc": "2026-10-10 21:09:54",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958537": [
        {
            "ioc_value": "3209102fb44250d32f04e6a4002de2c8895cf7fc",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.gcleaner",
            "malware_alias": null,
            "malware_printable": "GCleaner",
            "first_seen_utc": "2026-10-09 15:45:42",
            "last_seen_utc": "2026-10-10 21:09:55",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958531": [
        {
            "ioc_value": "be687d344be9e4df16978bd689caa3c64c6abe36",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-09 15:45:41",
            "last_seen_utc": "2026-10-10 21:09:53",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958532": [
        {
            "ioc_value": "fe7c856701c13f3bd2b3825fb61d47c8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-09 15:45:41",
            "last_seen_utc": "2026-10-10 21:09:53",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958533": [
        {
            "ioc_value": "af253ba15f9bf0fe7871ff377825abf02bd5fbea7c081c706d604a4a3cde843c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.kuiper",
            "malware_alias": null,
            "malware_printable": "Kuiper",
            "first_seen_utc": "2026-10-09 15:45:41",
            "last_seen_utc": "2026-10-10 21:09:54",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958529": [
        {
            "ioc_value": "a86f0faf0e8db1006b19130420ae3535",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:40",
            "last_seen_utc": "2026-10-10 21:09:52",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958530": [
        {
            "ioc_value": "448b653511a12b85616230b744e0c270a28593b2eff222ab432f0a077ad3e328",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-09 15:45:40",
            "last_seen_utc": "2026-10-10 21:09:53",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958527": [
        {
            "ioc_value": "0c4899656aa98daa195ecd372fe4bdeaaa4bec7a59212de2dba415a8b4ea310d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:39",
            "last_seen_utc": "2026-10-10 21:09:52",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958528": [
        {
            "ioc_value": "45a0874396a6acb3b0e28b74eb8dd4d427ebcd3e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:39",
            "last_seen_utc": "2026-10-10 21:09:52",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958524": [
        {
            "ioc_value": "77b3ca522f338bd41a022b34dc12e79b1ff6f650ae1d2801d2aaee99d965ab92",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:38",
            "last_seen_utc": "2026-10-10 21:09:51",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958525": [
        {
            "ioc_value": "b297d73c38eb0dfa01f1a7bbd8a43cb24ed17b92",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:38",
            "last_seen_utc": "2026-10-10 21:09:51",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958526": [
        {
            "ioc_value": "c8d00fa8c120721945a74cb657ac633d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:38",
            "last_seen_utc": "2026-10-10 21:09:52",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958520": [
        {
            "ioc_value": "6383d4f132c8470a93703e0c6912dd23",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:37",
            "last_seen_utc": "2026-10-10 21:09:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958521": [
        {
            "ioc_value": "40ea1e9b3f8237e7d7cfe16f94137355cd9884c22716375278d4478d26253dd1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:37",
            "last_seen_utc": "2026-10-10 21:09:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958522": [
        {
            "ioc_value": "864b8c04908a99461c7dd4d8fe5f306191ca785d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:37",
            "last_seen_utc": "2026-10-10 21:09:51",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958523": [
        {
            "ioc_value": "9875667f47bab0227f2f5bffa4124d94",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:37",
            "last_seen_utc": "2026-10-10 21:09:51",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958516": [
        {
            "ioc_value": "b53359642bc5bd72d6469056534d75aaf5b2af10",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:36",
            "last_seen_utc": "2026-10-10 21:09:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958517": [
        {
            "ioc_value": "2a1b23f25654c5cc384ecac832383e98",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:36",
            "last_seen_utc": "2026-10-10 21:09:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958518": [
        {
            "ioc_value": "2db4f1c4c73386907dfe6a4aa19186648149b0235dd38feea0b3db27cc83375a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:36",
            "last_seen_utc": "2026-10-10 21:09:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958519": [
        {
            "ioc_value": "dbdf2739163fa8125631469004574581db623b9f",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:36",
            "last_seen_utc": "2026-10-10 21:09:50",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958513": [
        {
            "ioc_value": "3432582e18fb8a8522984003e64c1466275094ac",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.yibackdoor",
            "malware_alias": null,
            "malware_printable": "YiBackdoor",
            "first_seen_utc": "2026-10-09 15:45:35",
            "last_seen_utc": "2026-10-10 21:09:48",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958514": [
        {
            "ioc_value": "43992ed63b048e2009585b4938200df2",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.yibackdoor",
            "malware_alias": null,
            "malware_printable": "YiBackdoor",
            "first_seen_utc": "2026-10-09 15:45:35",
            "last_seen_utc": "2026-10-10 21:09:48",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958515": [
        {
            "ioc_value": "fc26ae01b9226e767f1bf3e78ffc0e5f3ada519ef8eb74b43fef7094cac6510b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:35",
            "last_seen_utc": "2026-10-10 21:09:49",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958509": [
        {
            "ioc_value": "9a738a1e7ffc5bfbad53e1c345cb56b63c9e7750c243eeacf2d356ab0e6a86bf",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:34",
            "last_seen_utc": "2026-10-10 21:09:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958510": [
        {
            "ioc_value": "a933851ee02177dd73db98862f0f1048aa40aa84",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:34",
            "last_seen_utc": "2026-10-10 21:09:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958511": [
        {
            "ioc_value": "1eaf987d6b6750db2245109c9e39ffc2",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:34",
            "last_seen_utc": "2026-10-10 21:09:48",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958512": [
        {
            "ioc_value": "e52e65ed97e99d807394493f195bc62e5abe28db252fd060e3033bf6c2063e85",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.yibackdoor",
            "malware_alias": null,
            "malware_printable": "YiBackdoor",
            "first_seen_utc": "2026-10-09 15:45:34",
            "last_seen_utc": "2026-10-10 21:09:48",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958506": [
        {
            "ioc_value": "4cb7b82b2cbde85bfa1fb6d6affc673eb18ab20547dcb0ce3a0bec3ef6144876",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-09 15:45:33",
            "last_seen_utc": "2026-10-10 21:09:46",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958507": [
        {
            "ioc_value": "f926f62b26629f22bccb7ddb3ad9df7bc1760809",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-09 15:45:33",
            "last_seen_utc": "2026-10-10 21:09:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958508": [
        {
            "ioc_value": "b30e75738b06cca237b5a81cc15ad8a6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-09 15:45:33",
            "last_seen_utc": "2026-10-10 21:09:47",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958503": [
        {
            "ioc_value": "3ecaa29f595dfa5b433ba14f8c81cc14a614a8f78ff955e4c5a26ed1d71a7376",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:32",
            "last_seen_utc": "2026-10-10 21:09:46",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958504": [
        {
            "ioc_value": "0d6e2d5a8cb2fcbd1a428234fcc7efafe334eae6",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:32",
            "last_seen_utc": "2026-10-10 21:09:46",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958505": [
        {
            "ioc_value": "d24980d6d3a3cd3cad3f2eb62048779b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:32",
            "last_seen_utc": "2026-10-10 21:09:46",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958499": [
        {
            "ioc_value": "ae0a466748b9b9996188d9770ca9ebeb",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:31",
            "last_seen_utc": "2026-10-10 21:09:44",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958500": [
        {
            "ioc_value": "9797681d659fb3b6597629112f90265a7bf50a516453e1fae0a0e2a36cd709d8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:31",
            "last_seen_utc": "2026-10-10 21:09:45",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958501": [
        {
            "ioc_value": "9bd4e26fda4703b5d4ee1efed0ad04722bade08c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:31",
            "last_seen_utc": "2026-10-10 21:09:45",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958502": [
        {
            "ioc_value": "c6b475074fdd3c14d179add00066d082",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:31",
            "last_seen_utc": "2026-10-10 21:09:45",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958495": [
        {
            "ioc_value": "d7771fd1d8c06e83338a2391919e218449bc1e0b",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:30",
            "last_seen_utc": "2026-10-10 21:09:43",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958496": [
        {
            "ioc_value": "7e985941d1ab0148d279ca2e99b1392b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:30",
            "last_seen_utc": "2026-10-10 21:09:44",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958497": [
        {
            "ioc_value": "29fbd5445427c933eb1938ebea9fd05f784758ebfa68c22ac08441ef3286c9b1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:30",
            "last_seen_utc": "2026-10-10 21:09:44",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958498": [
        {
            "ioc_value": "beac55eaa69d1d3229249ef0abc14ee0d9026da4",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:30",
            "last_seen_utc": "2026-10-10 21:09:44",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958492": [
        {
            "ioc_value": "3b00f51e00d8e10bf513414a13a4da96c4abfc32",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.cloudeye",
            "malware_alias": "GuLoader,vbdropper",
            "malware_printable": "CloudEyE",
            "first_seen_utc": "2026-10-09 15:45:29",
            "last_seen_utc": "2026-10-10 21:09:43",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958493": [
        {
            "ioc_value": "d62d4b7811e37ce789b40ff9343e3458",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.cloudeye",
            "malware_alias": "GuLoader,vbdropper",
            "malware_printable": "CloudEyE",
            "first_seen_utc": "2026-10-09 15:45:29",
            "last_seen_utc": "2026-10-10 21:09:43",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958494": [
        {
            "ioc_value": "820c91b50591c4b825ef2914d25481278945d3a06d0692f1783be4cf8d97d24b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:29",
            "last_seen_utc": "2026-10-10 21:09:43",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958488": [
        {
            "ioc_value": "f7e58d2955db86e33b95939f645abc6f362cf86f396c548bdf22dbf707e5914a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:28",
            "last_seen_utc": "2026-10-10 21:09:42",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958489": [
        {
            "ioc_value": "d0662aa95fc1d76581356a0c6b1884bc43271da9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:28",
            "last_seen_utc": "2026-10-10 21:09:42",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958490": [
        {
            "ioc_value": "8ba88cb3e6a21e5b3f9e6047b266aa4f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:28",
            "last_seen_utc": "2026-10-10 21:09:42",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958491": [
        {
            "ioc_value": "7f1db334fd3302cf98dd4afddf6f90e98e2a496fe7e86bf1832b89d02f3d73c3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.cloudeye",
            "malware_alias": "GuLoader,vbdropper",
            "malware_printable": "CloudEyE",
            "first_seen_utc": "2026-10-09 15:45:28",
            "last_seen_utc": "2026-10-10 21:09:42",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958484": [
        {
            "ioc_value": "2fc54e662e890049651a6137a81efa3c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:27",
            "last_seen_utc": "2026-10-10 21:09:41",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958485": [
        {
            "ioc_value": "8d0f20e8ad3f80860c9f36105caa3528776e9f98573f2dac8ebc0c55325b62ac",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:27",
            "last_seen_utc": "2026-10-10 21:09:41",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958486": [
        {
            "ioc_value": "07a74911b66175da74abef77ea8021d2b952ee81",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:27",
            "last_seen_utc": "2026-10-10 21:09:41",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958487": [
        {
            "ioc_value": "2f765a561b23e461c38e65f40c7cc7f0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:27",
            "last_seen_utc": "2026-10-10 21:09:41",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958480": [
        {
            "ioc_value": "f18cee29bcd426cb80a02f0195eaf68f08d8e225",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:26",
            "last_seen_utc": "2026-10-10 21:09:39",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958481": [
        {
            "ioc_value": "abf4a82fc36da0c8918f7e8b7185d97c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:26",
            "last_seen_utc": "2026-10-10 21:09:40",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958482": [
        {
            "ioc_value": "121eb4be27d17c1c4320b912d75db79b337ad3a087a00a44dd94c2600ebc1304",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:26",
            "last_seen_utc": "2026-10-10 21:09:40",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958483": [
        {
            "ioc_value": "c54594a6f5bc2d5109c6afaa12a1eb934c9fa2bc",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:26",
            "last_seen_utc": "2026-10-10 21:09:40",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958477": [
        {
            "ioc_value": "91f5336715a543f9cbc45cbda6471b2a38aba4b8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:25",
            "last_seen_utc": "2026-10-10 21:09:39",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958478": [
        {
            "ioc_value": "e136fadd3494833f1c7d073df3a0772f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:25",
            "last_seen_utc": "2026-10-10 21:09:39",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958479": [
        {
            "ioc_value": "de007a3bc1cfcdf8985690b5127eb099292a3edfd6f4f7b462c65229011a669b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:25",
            "last_seen_utc": "2026-10-10 21:09:39",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958473": [
        {
            "ioc_value": "4e2d3b193a9bfb9f3a369a251a1b722450fa13d8fc193d3c872ebf1062783fde",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:24",
            "last_seen_utc": "2026-10-10 21:09:38",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958474": [
        {
            "ioc_value": "d9c19f966ff9cadfb515586114754d7ddf2381e7",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:24",
            "last_seen_utc": "2026-10-10 21:09:38",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958475": [
        {
            "ioc_value": "0f1d42cb6725d8194145cff1d3683634",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:24",
            "last_seen_utc": "2026-10-10 21:09:38",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958476": [
        {
            "ioc_value": "38dbcfe9e766a0b1a15c90e021febb42d75fd103328a6e1361fbb75ea1664f7e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:24",
            "last_seen_utc": "2026-10-10 21:09:39",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958470": [
        {
            "ioc_value": "aecef9efaad031a5d0a5ec25d49138708f93a69bc50a7cee73fc2352ba19a995",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:23",
            "last_seen_utc": "2026-10-10 21:09:37",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958471": [
        {
            "ioc_value": "214b94da576ed344820222edd216f333a4d02b37",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:23",
            "last_seen_utc": "2026-10-10 21:09:37",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958472": [
        {
            "ioc_value": "a48bdee475d7b4b1fb298a7a0477a1a8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:23",
            "last_seen_utc": "2026-10-10 21:09:37",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958467": [
        {
            "ioc_value": "3800a41b441e60803ac9ee6f700555619888b0b7a882ef557325f2b6b7843b2d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:22",
            "last_seen_utc": "2026-10-10 21:09:36",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958468": [
        {
            "ioc_value": "d12f0f5c10536e8ddb74a7dcc5422c32e4639384",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:22",
            "last_seen_utc": "2026-10-10 21:09:36",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958469": [
        {
            "ioc_value": "3064c11606319b47a0e30edd4cac21e3",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:45:22",
            "last_seen_utc": "2026-10-10 21:09:36",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958463": [
        {
            "ioc_value": "f7d83d241f4a45ea7a97ea74a1016dff",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:21",
            "last_seen_utc": "2026-10-10 21:09:35",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958464": [
        {
            "ioc_value": "01ec79ca328f90e03dd0c9ab0c115bacc279fa5eccea4cc03e4676dc9da78399",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:21",
            "last_seen_utc": "2026-10-10 21:09:35",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958465": [
        {
            "ioc_value": "7b8bf5e97e85caa5ef9889b78d6a72ea476d242a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:21",
            "last_seen_utc": "2026-10-10 21:09:35",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958466": [
        {
            "ioc_value": "6e4e02fb56c5d5f6b825b83f78543b45",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-09 15:45:21",
            "last_seen_utc": "2026-10-10 21:09:35",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958460": [
        {
            "ioc_value": "345bd23aae7e28c9b249b81a245f6c8d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:20",
            "last_seen_utc": "2026-10-10 21:09:34",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958461": [
        {
            "ioc_value": "b426e063f6e71de0d8c7bd6b1ed9c342e3aed4e16ff9d0b50154c67b899f8541",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:20",
            "last_seen_utc": "2026-10-10 21:09:34",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958462": [
        {
            "ioc_value": "c9e48064269a7f70a93ebc71ccc393e602f40f06",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:20",
            "last_seen_utc": "2026-10-10 21:09:34",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958456": [
        {
            "ioc_value": "e698540a6d357a092fac2f55f853731c7eeca504",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:19",
            "last_seen_utc": "2026-10-10 21:09:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958457": [
        {
            "ioc_value": "b85b33c6c8ac7242fb09c70c5c583a11",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:19",
            "last_seen_utc": "2026-10-10 21:09:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958458": [
        {
            "ioc_value": "84fd7e7de84bf9080ec938f944b81807faa769ab2e27a4d0a5f8596ff6dc0072",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:19",
            "last_seen_utc": "2026-10-10 21:09:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958459": [
        {
            "ioc_value": "eef695b8dfbe7783c81cd127c525543835cef9ec",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:19",
            "last_seen_utc": "2026-10-10 21:09:33",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958452": [
        {
            "ioc_value": "cf90ad8eef1b73e674f5dbbc12f8bbc4ee0ebc2b9485ddf5ef3cf5ce863f5333",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:18",
            "last_seen_utc": "2026-10-10 21:09:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958453": [
        {
            "ioc_value": "3243fb84a11143e574696e23eb114b4467275c35",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:18",
            "last_seen_utc": "2026-10-10 21:09:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958454": [
        {
            "ioc_value": "dcd580118706ee497e645311915996b0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:18",
            "last_seen_utc": "2026-10-10 21:09:32",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958455": [
        {
            "ioc_value": "e292d65b134653448ef4bcad23eaae8b08abefcbfcd360c3f0cd74adfee33495",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.valley_rat",
            "malware_alias": "Winos",
            "malware_printable": "ValleyRAT",
            "first_seen_utc": "2026-10-09 15:45:18",
            "last_seen_utc": "2026-10-10 21:09:32",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958449": [
        {
            "ioc_value": "3ea03e28c0a5a8c8a4910f26b2a1ee073053f76cbd9d21729dcec81543ac1617",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:17",
            "last_seen_utc": "2026-10-10 21:09:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958450": [
        {
            "ioc_value": "86ca4d6d00752507b1f12faf1bb55af0a6ec5db1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:17",
            "last_seen_utc": "2026-10-10 21:09:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958451": [
        {
            "ioc_value": "17c4d6e51c52e59ada1d644411d33015",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:17",
            "last_seen_utc": "2026-10-10 21:09:31",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958445": [
        {
            "ioc_value": "eb0da1bf4db13bbb8bc8fbf752274746",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "elf.watchbog",
            "malware_alias": null,
            "malware_printable": "WatchBog",
            "first_seen_utc": "2026-10-09 15:45:16",
            "last_seen_utc": "2026-10-10 21:09:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958446": [
        {
            "ioc_value": "22949b40865c3d6c9a2c7d7eae97c964b5fde63c1727ce74773d7aeb20be347a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:16",
            "last_seen_utc": "2026-10-10 21:09:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958447": [
        {
            "ioc_value": "db9d8725ab59d62827275531ce7216b3b9fe1e42",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:16",
            "last_seen_utc": "2026-10-10 21:09:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958448": [
        {
            "ioc_value": "4073eb55fca304f6aa94d9643286a503",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-09 15:45:16",
            "last_seen_utc": "2026-10-10 21:09:30",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958442": [
        {
            "ioc_value": "da72110692c7133a76dbf5e06aa571ef",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:15",
            "last_seen_utc": "2026-10-10 21:09:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958443": [
        {
            "ioc_value": "d0f40958cc03a11ec4fcd89223c6e6a9a134284e97993eeb2940f983d164dd11",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.watchbog",
            "malware_alias": null,
            "malware_printable": "WatchBog",
            "first_seen_utc": "2026-10-09 15:45:15",
            "last_seen_utc": "2026-10-10 21:09:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958444": [
        {
            "ioc_value": "f01698a5e796c1f541e82bf4ff6823f3f72f58a9",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "elf.watchbog",
            "malware_alias": null,
            "malware_printable": "WatchBog",
            "first_seen_utc": "2026-10-09 15:45:15",
            "last_seen_utc": "2026-10-10 21:09:29",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958438": [
        {
            "ioc_value": "c3fb8bf2e70eeb81ec7c4af3ea94b5997b2a91cb",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:14",
            "last_seen_utc": "2026-10-10 21:09:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958439": [
        {
            "ioc_value": "1efc935721d9adce730bca852752c8cc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:14",
            "last_seen_utc": "2026-10-10 21:09:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958440": [
        {
            "ioc_value": "e15e5d4f77fa217cf9ccf18fc0fff19e9b9e47d8c65413f2751904a14fcb8658",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:14",
            "last_seen_utc": "2026-10-10 21:09:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958441": [
        {
            "ioc_value": "230ba53a1d3f278b3d79ef797b70168b1671012e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-09 15:45:14",
            "last_seen_utc": "2026-10-10 21:09:28",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958435": [
        {
            "ioc_value": "126bb3ac12caaf4b5e1a4d765eeb10abd7b8cf4e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:13",
            "last_seen_utc": "2026-10-10 21:09:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958436": [
        {
            "ioc_value": "9a779afa0414abb6d525956e43b0d0a6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:13",
            "last_seen_utc": "2026-10-10 21:09:26",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958437": [
        {
            "ioc_value": "83935392c7f2e7e66fa4300e00fe063d250890e4b116d55e03e255661d3aa612",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:13",
            "last_seen_utc": "2026-10-10 21:09:27",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958431": [
        {
            "ioc_value": "729ef8e6a3cf1859811f3010b514416231e92ca66c4817cf8d6fce9df427a6a8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.guidloader",
            "malware_alias": null,
            "malware_printable": "GUIDLOADER",
            "first_seen_utc": "2026-10-09 15:45:12",
            "last_seen_utc": "2026-10-10 21:09:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958432": [
        {
            "ioc_value": "03a79e19baad8ace1bcd28e2a20a4fe2aa65ddaa",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.guidloader",
            "malware_alias": null,
            "malware_printable": "GUIDLOADER",
            "first_seen_utc": "2026-10-09 15:45:12",
            "last_seen_utc": "2026-10-10 21:09:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958433": [
        {
            "ioc_value": "8277f8350e12ecee116c42acb4aa48c0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.guidloader",
            "malware_alias": null,
            "malware_printable": "GUIDLOADER",
            "first_seen_utc": "2026-10-09 15:45:12",
            "last_seen_utc": "2026-10-10 21:09:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958434": [
        {
            "ioc_value": "b2c03ca07a9d844205f9c097e870fc3c54bfea34caef6ed6b907e7c887ba6665",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:12",
            "last_seen_utc": "2026-10-10 21:09:25",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958428": [
        {
            "ioc_value": "05e61a33cd451d1496c7cf05a3f7bf739708ad2198d1ef2f05dc1f5eb2236138",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-10-09 15:45:11",
            "last_seen_utc": "2026-10-10 21:09:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958429": [
        {
            "ioc_value": "6a1dda2436bda3e46f79b26c031838f8ebcb799d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-10-09 15:45:11",
            "last_seen_utc": "2026-10-10 21:09:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958430": [
        {
            "ioc_value": "cc028c2c3e90d682d77ef53545ce6b24",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-10-09 15:45:11",
            "last_seen_utc": "2026-10-10 21:09:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958424": [
        {
            "ioc_value": "2e9caca7825c171c8caaf7a500226303",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:10",
            "last_seen_utc": "2026-10-10 21:09:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958425": [
        {
            "ioc_value": "08954f9446234a2fafe12537884cfd684df960b6d28527f6777248518ab7e526",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.darktortilla",
            "malware_alias": null,
            "malware_printable": "DarkTortilla",
            "first_seen_utc": "2026-10-09 15:45:10",
            "last_seen_utc": "2026-10-10 21:09:23",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958426": [
        {
            "ioc_value": "c48a0969272a06ebd79066a6523f14a194229168",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.darktortilla",
            "malware_alias": null,
            "malware_printable": "DarkTortilla",
            "first_seen_utc": "2026-10-09 15:45:10",
            "last_seen_utc": "2026-10-10 21:09:23",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958427": [
        {
            "ioc_value": "7a35065b803f6f05dbce13ff68e1f815",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.darktortilla",
            "malware_alias": null,
            "malware_printable": "DarkTortilla",
            "first_seen_utc": "2026-10-09 15:45:10",
            "last_seen_utc": "2026-10-10 21:09:24",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958421": [
        {
            "ioc_value": "3ee38b944e5c83922f99641846f7db0c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 15:45:09",
            "last_seen_utc": "2026-10-10 21:09:21",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958422": [
        {
            "ioc_value": "c23a5d89f60bc65b7bf92b6bcca9311d704611b7482f63befee64096f047ac32",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:09",
            "last_seen_utc": "2026-10-10 21:09:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958423": [
        {
            "ioc_value": "b03b862ff5935df252905ea9d6da3689d057e874",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-09 15:45:09",
            "last_seen_utc": "2026-10-10 21:09:22",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958417": [
        {
            "ioc_value": "577931a73b317cd0a5863be78a1fe1afbb615c5a",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.dyepack",
            "malware_alias": "BanSwift,swift",
            "malware_printable": "DYEPACK",
            "first_seen_utc": "2026-10-09 15:45:08",
            "last_seen_utc": "2026-10-10 21:09:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958418": [
        {
            "ioc_value": "ca74f32dd56f3ad2e51dd1ec54643681",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.dyepack",
            "malware_alias": "BanSwift,swift",
            "malware_printable": "DYEPACK",
            "first_seen_utc": "2026-10-09 15:45:08",
            "last_seen_utc": "2026-10-10 21:09:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958419": [
        {
            "ioc_value": "b4cc5ac328afd0e7eaf16216879046367e083279bfdb831da3a53c8a31df3d1b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 15:45:08",
            "last_seen_utc": "2026-10-10 21:09:21",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958420": [
        {
            "ioc_value": "440d850ca84790200ad4743f82f23e4393cb95be",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 15:45:08",
            "last_seen_utc": "2026-10-10 21:09:21",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958414": [
        {
            "ioc_value": "114545bb479dc3876a93a771136b210ed0bf7bc1",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.xenorat",
            "malware_alias": null,
            "malware_printable": "XenoRAT",
            "first_seen_utc": "2026-10-09 15:45:07",
            "last_seen_utc": "2026-10-10 21:09:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958415": [
        {
            "ioc_value": "dea6360a06563989ea46c2132658242c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.xenorat",
            "malware_alias": null,
            "malware_printable": "XenoRAT",
            "first_seen_utc": "2026-10-09 15:45:07",
            "last_seen_utc": "2026-10-10 21:09:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958416": [
        {
            "ioc_value": "d25a3a858e28faa68ca6c624d7d19350c11ac798c346be3067307463e40aaff1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.dyepack",
            "malware_alias": "BanSwift,swift",
            "malware_printable": "DYEPACK",
            "first_seen_utc": "2026-10-09 15:45:07",
            "last_seen_utc": "2026-10-10 21:09:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958410": [
        {
            "ioc_value": "46601bf92dace2d244fe62f409f9919ef919afef45109bffc9629397fcc76170",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:06",
            "last_seen_utc": "2026-10-10 21:09:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958411": [
        {
            "ioc_value": "61797c9f87d34ea7dda0a93166db2a5c5adcbf1c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:06",
            "last_seen_utc": "2026-10-10 21:09:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958412": [
        {
            "ioc_value": "44c6c41450202d71fb769bcfff376ba4",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 15:45:06",
            "last_seen_utc": "2026-10-10 21:09:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958413": [
        {
            "ioc_value": "edd8babd11621c8ec12ea7a01c141615089a77d755fab43b30507da28653558d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.xenorat",
            "malware_alias": null,
            "malware_printable": "XenoRAT",
            "first_seen_utc": "2026-10-09 15:45:06",
            "last_seen_utc": "2026-10-10 21:09:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958407": [
        {
            "ioc_value": "024d5533d9cd346418c7780706410fca28f88e33291e8ca6b382299dfea043da",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vipkeylogger",
            "malware_alias": null,
            "malware_printable": "VIP Keylogger",
            "first_seen_utc": "2026-10-09 15:45:05",
            "last_seen_utc": "2026-10-10 21:09:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958408": [
        {
            "ioc_value": "bfa6c39cdca285754eb02370e2da26645b0d7709",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vipkeylogger",
            "malware_alias": null,
            "malware_printable": "VIP Keylogger",
            "first_seen_utc": "2026-10-09 15:45:05",
            "last_seen_utc": "2026-10-10 21:09:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958409": [
        {
            "ioc_value": "d1b18404eb25fb66030bd1e426a639c5",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vipkeylogger",
            "malware_alias": null,
            "malware_printable": "VIP Keylogger",
            "first_seen_utc": "2026-10-09 15:45:05",
            "last_seen_utc": "2026-10-10 21:09:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958405": [
        {
            "ioc_value": "793a5ad9ca1cb1fd67c032bfb66d5ba715552361",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-10-09 15:45:04",
            "last_seen_utc": "2026-10-10 21:09:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958406": [
        {
            "ioc_value": "01f9447f60239d25e1c86d1da8dd1534",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-10-09 15:45:04",
            "last_seen_utc": "2026-10-10 21:09:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958404": [
        {
            "ioc_value": "db4732a4b2646f6ddef351784943f58c27311215807a9ba670e9f687366e2a43",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.krakenkeylogger",
            "malware_alias": null,
            "malware_printable": "KrakenKeylogger",
            "first_seen_utc": "2026-10-09 15:45:03",
            "last_seen_utc": "2026-10-10 21:09:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1958403": [
        {
            "ioc_value": "https://94.237.14.115",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 15:40:21",
            "last_seen_utc": "2026-10-09 20:49:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e2b3d893f7fe9400b37f390e6c87e979bd5201cdd149816cd70e942fa0ebac74/",
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958400": [
        {
            "ioc_value": "alimousa.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:39:44",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958401": [
        {
            "ioc_value": "alrehansign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:39:44",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958402": [
        {
            "ioc_value": "alifilms.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:39:44",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958398": [
        {
            "ioc_value": "angkasa138eeh.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:39:43",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958399": [
        {
            "ioc_value": "angkasa138juu.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:39:43",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958394": [
        {
            "ioc_value": "angkasa138oww.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:42",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958395": [
        {
            "ioc_value": "angkasa138stars.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:42",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958396": [
        {
            "ioc_value": "angkasa138bagi.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:42",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958390": [
        {
            "ioc_value": "angkasa138iwe.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:41",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958391": [
        {
            "ioc_value": "amp77bet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:41",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958392": [
        {
            "ioc_value": "angkasa138oue.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:41",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958393": [
        {
            "ioc_value": "angkasa138sot.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:41",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958386": [
        {
            "ioc_value": "allstates-us.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:40",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958387": [
        {
            "ioc_value": "angkasa138maho.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:40",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958388": [
        {
            "ioc_value": "alljob.bd",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:40",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958389": [
        {
            "ioc_value": "angkasa138buah.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:40",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958385": [
        {
            "ioc_value": "angkasa138st.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:29:39",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958384": [
        {
            "ioc_value": "secretanselma.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 15:23:45",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958383": [
        {
            "ioc_value": "angkasa138star.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:39",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958379": [
        {
            "ioc_value": "angkasa138muh.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:38",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958380": [
        {
            "ioc_value": "angkasa138bruh.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:38",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958381": [
        {
            "ioc_value": "angkasa138.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:38",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958382": [
        {
            "ioc_value": "angkasa138toh.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:38",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958375": [
        {
            "ioc_value": "angkasa138orian.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:37",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958376": [
        {
            "ioc_value": "angkasa138nihh.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:37",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958377": [
        {
            "ioc_value": "angkasa138now.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:37",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958378": [
        {
            "ioc_value": "ampsinar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:37",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958371": [
        {
            "ioc_value": "angkasa138uei.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:36",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958372": [
        {
            "ioc_value": "angkasa138mbur.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:36",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958373": [
        {
            "ioc_value": "angkasa138mmx.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:36",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958374": [
        {
            "ioc_value": "angkasa138original.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:36",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958370": [
        {
            "ioc_value": "angkasa1318ril.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:19:35",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958369": [
        {
            "ioc_value": "fzhcf43291.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 15:18:59",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958368": [
        {
            "ioc_value": "sanxuatmay.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-09 15:17:40",
            "last_seen_utc": "2026-10-09 18:01:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1958363": [
        {
            "ioc_value": "angkasa138cik.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:34",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958364": [
        {
            "ioc_value": "angkasa138come.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:34",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958365": [
        {
            "ioc_value": "amberden.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:34",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958366": [
        {
            "ioc_value": "amberblog.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:34",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958359": [
        {
            "ioc_value": "amberblogs.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:33",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958360": [
        {
            "ioc_value": "angkasa138login.world",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:33",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958361": [
        {
            "ioc_value": "angkasa138buah.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:33",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958362": [
        {
            "ioc_value": "amberdiary.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:33",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958355": [
        {
            "ioc_value": "angkasa138loe.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:32",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958356": [
        {
            "ioc_value": "angkasa138fly.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:32",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958357": [
        {
            "ioc_value": "angkasa138mbos.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:32",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958358": [
        {
            "ioc_value": "angkasa138cuks.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:32",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958353": [
        {
            "ioc_value": "angkasa138ones.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:31",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958354": [
        {
            "ioc_value": "angkasa138moe.cyou",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 15:09:31",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958352": [
        {
            "ioc_value": "crawl-66-249-79-33.googlebot.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 15:09:21",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958351": [
        {
            "ioc_value": "91.92.43.233:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 15:04:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6b0afb349635fb95996f7cc4e5ee22feb695df41ab2a86024f9603013e94a8e5/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958348": [
        {
            "ioc_value": "amberdaily.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:54:03",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958349": [
        {
            "ioc_value": "amberbulletins.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:54:03",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958347": [
        {
            "ioc_value": "aliyunmail.app",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:54:02",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958326": [
        {
            "ioc_value": "143.246.213.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-10-09 14:51:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/63427470-fbf9-4698-8d93-5024f1c17820/",
            "tags": "IRAHook,RAT,Stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958327": [
        {
            "ioc_value": "dd16083e8b555de6f1852da430ca2f2192366bae191a2674ae2464a43a4f94d5",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 14:51:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/dd16083e8b555de6f1852da430ca2f2192366bae191a2674ae2464a43a4f94d5",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958328": [
        {
            "ioc_value": "165.22.244.100:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 14:51:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958330": [
        {
            "ioc_value": "135.136.140.39:2445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 14:51:16",
            "last_seen_utc": "2026-10-11 08:08:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "basefri,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958345": [
        {
            "ioc_value": "888slotgac0rwin.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:34:01",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958346": [
        {
            "ioc_value": "3jmslogistics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:34:01",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958341": [
        {
            "ioc_value": "888slotmaxwin1.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:34:00",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958342": [
        {
            "ioc_value": "888slotmaxwin01.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:34:00",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958343": [
        {
            "ioc_value": "1eu-sharepoint.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:34:00",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958344": [
        {
            "ioc_value": "77betsports01.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:34:00",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958339": [
        {
            "ioc_value": "777slotmaxwin01.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:33:59",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958340": [
        {
            "ioc_value": "2dollarsubscriptions.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:33:59",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958338": [
        {
            "ioc_value": "lavender222.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 14:33:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958337": [
        {
            "ioc_value": "https://aailc.co/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 14:30:52",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/aailc.co",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958336": [
        {
            "ioc_value": "222slotmaxwin1.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:23:58",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958335": [
        {
            "ioc_value": "google-proxy-74-125-213-43.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 14:12:39",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958333": [
        {
            "ioc_value": "812-group.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:08:24",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958334": [
        {
            "ioc_value": "dharaniinfrastructure.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:08:24",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958331": [
        {
            "ioc_value": "777slotgac0rwin.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:08:23",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958332": [
        {
            "ioc_value": "777slotmaxwin1.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 14:08:23",
            "last_seen_utc": "2026-10-09 21:02:39",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958329": [
        {
            "ioc_value": "3.24.186.0:4449",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 14:05:30",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/edd8babd11621c8ec12ea7a01c141615089a77d755fab43b30507da28653558d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958325": [
        {
            "ioc_value": "lakihila.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 13:33:10",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958324": [
        {
            "ioc_value": "ikvg8azi.misle.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 13:30:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x0f14,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958323": [
        {
            "ioc_value": "qvdst48061.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 13:26:44",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958322": [
        {
            "ioc_value": "seaopencd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 13:19:20",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958299": [
        {
            "ioc_value": "104.248.144.172:6738",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-09 13:05:07",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0f81469cc7638ba7c82eaddbd6b3c20a,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958300": [
        {
            "ioc_value": "b55e16170cbba64cb8fe432d2004c0b011db6318ed41dd359637a2afe9d6545b",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b55e16170cbba64cb8fe432d2004c0b011db6318ed41dd359637a2afe9d6545b",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958302": [
        {
            "ioc_value": "3e0b7f50928f8b8f08f1527129a5c8aad50df66e88f2c34a3fd3056081e26d77",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/3e0b7f50928f8b8f08f1527129a5c8aad50df66e88f2c34a3fd3056081e26d77",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958307": [
        {
            "ioc_value": "https://pro.jasperwater.info/auth/dashboard-cache",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-10-09 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958321": [
        {
            "ioc_value": "39.104.200.49:9655",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-10-09 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958308": [
        {
            "ioc_value": "pro.jasperwater.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-10-09 13:05:05",
            "last_seen_utc": "2026-10-09 12:10:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958309": [
        {
            "ioc_value": "https://pro.jasperwater.info/auth/permission-render.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "js.smartapesg",
            "malware_alias": "HANEYMANEY,ZPHP",
            "malware_printable": "SmartApeSG",
            "first_seen_utc": "2026-10-09 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "SmartApeSG",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1958310": [
        {
            "ioc_value": "194.182.79.61:53898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 13:05:04",
            "last_seen_utc": "2026-10-11 04:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Local,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958313": [
        {
            "ioc_value": "deba43734e342776a2724c6cf12557aa7bbbd93200a4f2bfa8f2e7f7ef1b56a8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 13:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/deba43734e342776a2724c6cf12557aa7bbbd93200a4f2bfa8f2e7f7ef1b56a8",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958320": [
        {
            "ioc_value": "217.60.103.15:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 13:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958315": [
        {
            "ioc_value": "217.60.242.27:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 13:05:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958319": [
        {
            "ioc_value": "207.154.219.20:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 12:54:33",
            "last_seen_utc": "2026-10-10 18:32:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958318": [
        {
            "ioc_value": "gkpuc66191.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 12:41:31",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958317": [
        {
            "ioc_value": "mars-uae.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 12:32:47",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958316": [
        {
            "ioc_value": "restaurant.moovent.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 12:32:44",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958314": [
        {
            "ioc_value": "48ypnsgk.porel.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-09 12:28:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958312": [
        {
            "ioc_value": "http://139.135.59.180:50268/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-09 12:19:11",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/139.135.59.180",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1958311": [
        {
            "ioc_value": "http://82.209.204.6:43726/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-10-09 12:19:10",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/82.209.204.6",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1958306": [
        {
            "ioc_value": "b926c66f511842d0b2fb8d09d7bba064d5385f28f2a4d71e3bf230eb5a2fcde1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 12:06:15",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958305": [
        {
            "ioc_value": "708c3628746961658e1b16c2af396aaa362c868f28681fc7025b69733057b4af",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-09 12:06:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "elf,Mirai",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1958304": [
        {
            "ioc_value": "google-proxy-66-249-88-198.google.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 12:01:01",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "GIF,PHP,webshell,WordPress,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958303": [
        {
            "ioc_value": "45.144.172.49:32789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-09 11:54:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958301": [
        {
            "ioc_value": "hofugo.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 11:41:38",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958298": [
        {
            "ioc_value": "hakaxylu.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 11:31:43",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958291": [
        {
            "ioc_value": "708329a7a39e5391fe3e938933e5758b685d080146c0b703f1805e179d2bae8d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 11:13:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/708329a7a39e5391fe3e938933e5758b685d080146c0b703f1805e179d2bae8d",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958295": [
        {
            "ioc_value": "45.135.194.116:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 11:13:16",
            "last_seen_utc": "2026-10-09 11:28:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958296": [
        {
            "ioc_value": "199.101.198.165:32043",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 11:13:16",
            "last_seen_utc": "2026-10-11 08:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,TONERO",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958297": [
        {
            "ioc_value": "http://homecor.click:6527/imports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-09 11:12:13",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1958294": [
        {
            "ioc_value": "juynu31926.workers.dev",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "php.shin_webshell",
            "malware_alias": null,
            "malware_printable": "php.shin_webshell",
            "first_seen_utc": "2026-10-09 10:53:18",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": null,
            "tags": "Cloudflare,GIF,PHP,webshell,WordPress,workers.dev,wp-admin",
            "anonymous": 0,
            "reporter": "xscon"
        }
    ],
    "1958293": [
        {
            "ioc_value": "67.220.71.211:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 10:52:11",
            "last_seen_utc": "2026-10-10 10:51:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958292": [
        {
            "ioc_value": "45.127.32.69:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 10:52:10",
            "last_seen_utc": "2026-10-10 10:51:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958250": [
        {
            "ioc_value": "4dcb0202fe8b2d4d7b183764e38184cd6ed50132786cc7e7d1f7f4bce1dd6f3d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.xmrig",
            "malware_alias": null,
            "malware_printable": "xmrig",
            "first_seen_utc": "2026-10-09 10:48:34",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://threatcluster.io/cluster/critical-vulnerabilities-in-ahsaycbs-exploited-for-remote-co-537313ea",
            "tags": null,
            "anonymous": 0,
            "reporter": "threatcluster"
        }
    ],
    "1958240": [
        {
            "ioc_value": "172.94.99.29:1408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-09 10:48:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "RAT,XWorm",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958249": [
        {
            "ioc_value": "481728a7c9c4c02be07051d9c1958d902ea6397ebb8952ab83944818e3d25d21",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.xmrig",
            "malware_alias": null,
            "malware_printable": "xmrig",
            "first_seen_utc": "2026-10-09 10:48:33",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://threatcluster.io/cluster/critical-vulnerabilities-in-ahsaycbs-exploited-for-remote-co-537313ea",
            "tags": null,
            "anonymous": 0,
            "reporter": "threatcluster"
        }
    ],
    "1958258": [
        {
            "ioc_value": "192.3.73.139:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 10:48:32",
            "last_seen_utc": "2026-10-11 07:15:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,garus & alaskaa,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958259": [
        {
            "ioc_value": "192.3.73.139:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 10:48:32",
            "last_seen_utc": "2026-10-11 07:18:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,garus & alaskaa,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958260": [
        {
            "ioc_value": "192.3.73.139:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 10:48:31",
            "last_seen_utc": "2026-10-11 02:13:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,garus & alaskaa,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958263": [
        {
            "ioc_value": "1rvrental.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 10:48:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://threatfox.abuse.ch/ioc/1958195/",
            "tags": null,
            "anonymous": 0,
            "reporter": "ghozt"
        }
    ],
    "1958264": [
        {
            "ioc_value": "http://1rvrental.com/r",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 10:48:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ghozt"
        }
    ],
    "1958265": [
        {
            "ioc_value": "https://1rvrental.com/g.php",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 10:48:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "ghozt"
        }
    ],
    "1958266": [
        {
            "ioc_value": "edgnltatqptann.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-10-09 10:48:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://blakekwhite.com/research/clickfix-github-desktop-backdoor/",
            "tags": null,
            "anonymous": 0,
            "reporter": "ghozt"
        }
    ],
    "1958267": [
        {
            "ioc_value": "aeyibtnr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-10-09 10:48:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://blakekwhite.com/research/clickfix-github-desktop-backdoor/",
            "tags": null,
            "anonymous": 0,
            "reporter": "ghozt"
        }
    ],
    "1958268": [
        {
            "ioc_value": "anwhinweudee.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.deerstealer",
            "malware_alias": null,
            "malware_printable": "DeerStealer",
            "first_seen_utc": "2026-10-09 10:48:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://blakekwhite.com/research/clickfix-github-desktop-backdoor/",
            "tags": null,
            "anonymous": 0,
            "reporter": "ghozt"
        }
    ],
    "1958281": [
        {
            "ioc_value": "141.98.10.150:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 10:48:27",
            "last_seen_utc": "2026-10-11 08:19:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,MicrosoftOutlook,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958282": [
        {
            "ioc_value": "5.83.134.80:14593",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 10:48:26",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/a96874d626135f7cb4b1f6727275f5109442e39800299b91376fe22af870aac2/",
            "tags": "arm,cowrie,elf,honeypot,iot,tadashi,telnet",
            "anonymous": 0,
            "reporter": "ksi_digital"
        }
    ],
    "1958285": [
        {
            "ioc_value": "185.212.44.20:443",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 10:48:25",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "https://any.run/report/31ad018488bf0df24a4c1814ce70aa45c5f6459f15b6aef74bcb0aa7fa3e7397/0f810615-878b-477d-885d-81213e1360dc",
            "tags": "C2,Cobalt strike",
            "anonymous": 0,
            "reporter": "DamanpreetSingh"
        }
    ],
    "1958286": [
        {
            "ioc_value": "3cbb6ca0dccfdd22f337f57ac9ac661f8a2e78d5fc42a55e64ca86691e7c19ae",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "osx.amos",
            "malware_alias": "Atomic macOS Stealer",
            "malware_printable": "AMOS",
            "first_seen_utc": "2026-10-09 10:48:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/3cbb6ca0dccfdd22f337f57ac9ac661f8a2e78d5fc42a55e64ca86691e7c19ae",
            "tags": "AMOS,ClickFix,Foxveil,macOS,quill",
            "anonymous": 0,
            "reporter": "c4ffeine"
        }
    ],
    "1958290": [
        {
            "ioc_value": "193.178.158.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-10-09 10:36:02",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=193.178.158.71",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958288": [
        {
            "ioc_value": "https://profitrollellc.com/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 10:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/profitrollellc.com",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958289": [
        {
            "ioc_value": "https://mahoomahtab.ir/",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 10:30:53",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://clickfix.carsonww.com/domains/mahoomahtab.ir",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "CarsonWilliams"
        }
    ],
    "1958287": [
        {
            "ioc_value": "https://madrid-9.club/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-10-09 10:25:12",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "WARDENStealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1958283": [
        {
            "ioc_value": "xya.supercrone.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 10:20:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958284": [
        {
            "ioc_value": "feds.iphaven.qzz.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 10:20:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958279": [
        {
            "ioc_value": "95.133.228.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-09 09:45:55",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958278": [
        {
            "ioc_value": "68.168.219.222:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 09:45:38",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958277": [
        {
            "ioc_value": "47.80.241.141:64435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 09:45:28",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958276": [
        {
            "ioc_value": "38.76.199.254:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 09:45:13",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958275": [
        {
            "ioc_value": "192.159.99.76:2010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-09 09:44:12",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958274": [
        {
            "ioc_value": "185.117.89.70:8415",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 09:44:02",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958273": [
        {
            "ioc_value": "151.243.126.22:26443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-10-09 09:43:40",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958272": [
        {
            "ioc_value": "139.180.213.153:8441",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 09:43:32",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958271": [
        {
            "ioc_value": "128.90.105.227:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 09:43:24",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958270": [
        {
            "ioc_value": "103.149.91.234:32081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-09 09:43:11",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958237": [
        {
            "ioc_value": "130.12.180.212:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 08:53:51",
            "last_seen_utc": "2026-10-11 09:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958220": [
        {
            "ioc_value": "157.20.182.14:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-09 08:05:05",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957899": [
        {
            "ioc_value": "https://kl.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 06:04:55",
            "last_seen_utc": "2026-10-11 07:31:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2f3c6fb2d82ed66e2e45208cd1c7edd1,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957976": [
        {
            "ioc_value": "http://193.178.158.71/b894jfjw/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-10-09 06:04:52",
            "last_seen_utc": "2026-10-11 09:28:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "amadey,c2,ce6e4f",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957985": [
        {
            "ioc_value": "141.98.10.127:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 06:04:52",
            "last_seen_utc": "2026-10-11 09:25:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BIN,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958011": [
        {
            "ioc_value": "94.154.40.108:1413",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 06:04:51",
            "last_seen_utc": "2026-10-11 05:14:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,tor05g",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958024": [
        {
            "ioc_value": "https://172.105.93.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 06:04:50",
            "last_seen_utc": "2026-10-11 09:49:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "22528fe54e097936120ba50e16c6a235,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958105": [
        {
            "ioc_value": "https://172.238.108.43",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 06:04:49",
            "last_seen_utc": "2026-10-11 09:48:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e388d47768eb76b50f1e463971fc7294,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958111": [
        {
            "ioc_value": "https://ik.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 06:04:47",
            "last_seen_utc": "2026-10-11 07:30:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "62c0c8e44e6a373d8d66802e4ab16faf,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958133": [
        {
            "ioc_value": "https://ik.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 06:04:46",
            "last_seen_utc": "2026-10-11 07:32:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "18094918b35ccec7caaf0b129e6d0490,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958156": [
        {
            "ioc_value": "172.111.139.12:2301",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-09 06:04:45",
            "last_seen_utc": "2026-10-09 19:15:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,nuevos 07,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958167": [
        {
            "ioc_value": "https://nr.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-09 06:04:43",
            "last_seen_utc": "2026-10-09 16:02:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "18639d8e3c129270e4d9f4328b3819a1,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958180": [
        {
            "ioc_value": "46.101.164.65:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-09 06:04:39",
            "last_seen_utc": "2026-10-10 02:19:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1958143": [
        {
            "ioc_value": "124.221.191.237:3668",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 03:45:40",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958142": [
        {
            "ioc_value": "1.12.253.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-09 03:45:35",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958135": [
        {
            "ioc_value": "5.180.27.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-09 03:05:05",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1958028": [
        {
            "ioc_value": "45.207.8.36:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-08 23:45:55",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958025": [
        {
            "ioc_value": "https://172.236.214.203",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 23:25:22",
            "last_seen_utc": "2026-10-09 12:00:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/38dbcfe9e766a0b1a15c90e021febb42d75fd103328a6e1361fbb75ea1664f7e/",
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1958009": [
        {
            "ioc_value": "102.220.161.194:10213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.cecbot",
            "malware_alias": null,
            "malware_printable": "CECbot",
            "first_seen_utc": "2026-10-08 21:58:19",
            "last_seen_utc": "2026-10-10 22:03:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/cecbot",
            "tags": "android,botnet,cecbot,ddos",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958007": [
        {
            "ioc_value": "47.237.95.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 21:55:37",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958008": [
        {
            "ioc_value": "47.85.194.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 21:55:37",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1958005": [
        {
            "ioc_value": "134.122.91.85:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-08 21:54:21",
            "last_seen_utc": "2026-10-10 10:20:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957993": [
        {
            "ioc_value": "verifiedbmsells.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957994": [
        {
            "ioc_value": "wealthywealth.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957995": [
        {
            "ioc_value": "www.heritagemusical.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957996": [
        {
            "ioc_value": "www.smartlivingstyle.cat",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957988": [
        {
            "ioc_value": "fernandeseneri.adv.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:28",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957990": [
        {
            "ioc_value": "narowalgymkhana.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:28",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957991": [
        {
            "ioc_value": "productpalace.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:28",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957992": [
        {
            "ioc_value": "tesafco.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:28",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957986": [
        {
            "ioc_value": "austin-zhao.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:27",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957987": [
        {
            "ioc_value": "clickfix.jordiserrano.me",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 21:17:27",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,HwFingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957970": [
        {
            "ioc_value": "43.157.80.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 20:51:26",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957971": [
        {
            "ioc_value": "43.166.72.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 20:51:26",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957972": [
        {
            "ioc_value": "43.166.73.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 20:51:26",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957973": [
        {
            "ioc_value": "43.173.102.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 20:51:26",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957974": [
        {
            "ioc_value": "43.173.37.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-08 20:51:26",
            "last_seen_utc": "2026-10-11 01:39:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957897": [
        {
            "ioc_value": "95.179.183.3:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-10-08 19:45:41",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957896": [
        {
            "ioc_value": "46.151.182.67:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:45:14",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957895": [
        {
            "ioc_value": "45.88.91.164:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:45:12",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957894": [
        {
            "ioc_value": "43.133.165.151:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-08 19:45:01",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957893": [
        {
            "ioc_value": "36.50.134.86:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-08 19:44:56",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957892": [
        {
            "ioc_value": "31.57.147.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:44:52",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957891": [
        {
            "ioc_value": "217.60.103.15:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957890": [
        {
            "ioc_value": "217.60.102.37:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 19:44:41",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957889": [
        {
            "ioc_value": "207.56.3.27:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:44:20",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957887": [
        {
            "ioc_value": "190.102.40.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:44:05",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957888": [
        {
            "ioc_value": "192.121.171.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-10-08 19:44:05",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957886": [
        {
            "ioc_value": "186.169.33.116:9031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-08 19:44:02",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957883": [
        {
            "ioc_value": "167.88.173.162:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957884": [
        {
            "ioc_value": "167.88.173.162:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957885": [
        {
            "ioc_value": "167.88.173.162:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957882": [
        {
            "ioc_value": "157.20.182.15:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957880": [
        {
            "ioc_value": "154.92.252.61:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-08 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957881": [
        {
            "ioc_value": "156.238.120.71:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957878": [
        {
            "ioc_value": "154.92.252.59:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-08 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957879": [
        {
            "ioc_value": "154.92.252.60:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-08 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957877": [
        {
            "ioc_value": "154.127.53.182:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:36",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957876": [
        {
            "ioc_value": "146.190.247.89:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-10-08 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957875": [
        {
            "ioc_value": "137.184.214.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957874": [
        {
            "ioc_value": "108.186.112.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-08 19:43:15",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957873": [
        {
            "ioc_value": "104.243.248.63:402",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 19:43:11",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957846": [
        {
            "ioc_value": "5.180.27.57:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 19:05:06",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957835": [
        {
            "ioc_value": "172.94.58.29:2303",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-08 18:20:52",
            "last_seen_utc": "2026-10-10 15:17:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,WinProtection2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957642": [
        {
            "ioc_value": "haergreve.lol",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-10-08 17:58:22",
            "last_seen_utc": "2026-10-09 15:12:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1957828": [
        {
            "ioc_value": "64.227.153.168:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 17:53:03",
            "last_seen_utc": "2026-10-10 18:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957631": [
        {
            "ioc_value": "138.68.102.151:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957632": [
        {
            "ioc_value": "142.93.142.227:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957633": [
        {
            "ioc_value": "161.35.151.100:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957634": [
        {
            "ioc_value": "161.35.203.167:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957635": [
        {
            "ioc_value": "161.35.39.220:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957636": [
        {
            "ioc_value": "167.172.60.211:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957637": [
        {
            "ioc_value": "168.144.243.52:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957638": [
        {
            "ioc_value": "178.128.197.163:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957639": [
        {
            "ioc_value": "178.128.245.68:7061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.drifter",
            "malware_alias": "Dongfeng",
            "malware_printable": "Drifter",
            "first_seen_utc": "2026-10-08 16:53:50",
            "last_seen_utc": "2026-10-10 16:56:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/drifter",
            "tags": "android,botnet,ddos,dongfeng,drifter",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1957586": [
        {
            "ioc_value": "3f790d1fc0bae05463f75c5c2fda33b7616230a361630da56e87f7cf26e5fd89",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-10-08 16:39:55",
            "last_seen_utc": "2026-10-09 15:45:54",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "9d2ca3,Coinminer,dropped-by-Amadey,exe",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1957421": [
        {
            "ioc_value": "06aebc4b151876e8c1c9e118f90e14aba11b284d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:34",
            "last_seen_utc": "2026-10-09 15:46:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957422": [
        {
            "ioc_value": "596dc288e8914898b0be9d57a0e3d277",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:34",
            "last_seen_utc": "2026-10-09 15:46:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957418": [
        {
            "ioc_value": "b86377694a68f49df4848d2e97e7ba1a877a5a41",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:33:33",
            "last_seen_utc": "2026-10-09 15:46:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957419": [
        {
            "ioc_value": "12d814fd207528a5a717d5165935234d",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:33:33",
            "last_seen_utc": "2026-10-09 15:46:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957420": [
        {
            "ioc_value": "64506ae267aed8afa5cfbb41ca8f5677600747f02fe27b8d8d926d12e3ad99f2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:33",
            "last_seen_utc": "2026-10-09 15:46:19",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957416": [
        {
            "ioc_value": "7a111b2437d904a3d77e6068e0435283e4666648",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:33:32",
            "last_seen_utc": "2026-10-09 15:46:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957417": [
        {
            "ioc_value": "62b999539aa9527c40af688337d128f9",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:33:32",
            "last_seen_utc": "2026-10-09 15:46:18",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957413": [
        {
            "ioc_value": "3ae41014b7ff7675d13a1197ab40f05d1dc48a45",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.rn_stealer",
            "malware_alias": null,
            "malware_printable": "RN Stealer",
            "first_seen_utc": "2026-10-08 14:33:31",
            "last_seen_utc": "2026-10-09 15:46:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957414": [
        {
            "ioc_value": "0ad85d51df8c276818ef4c45cad6cf63",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.rn_stealer",
            "malware_alias": null,
            "malware_printable": "RN Stealer",
            "first_seen_utc": "2026-10-08 14:33:31",
            "last_seen_utc": "2026-10-09 15:46:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957415": [
        {
            "ioc_value": "0f37ed17ba77ce94b880e16f1e38464ebaf5cd907666cf75075df16d9a166092",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:33:31",
            "last_seen_utc": "2026-10-09 15:46:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957411": [
        {
            "ioc_value": "3bf180fb81eaded9afa930e69af74b81",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-08 14:33:30",
            "last_seen_utc": "2026-10-09 15:46:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957412": [
        {
            "ioc_value": "69dafc3b40a5b0e5eddc7cba6ec32ca7316b7e5405d8c6d5adfbccc4c06620c0",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.rn_stealer",
            "malware_alias": null,
            "malware_printable": "RN Stealer",
            "first_seen_utc": "2026-10-08 14:33:30",
            "last_seen_utc": "2026-10-09 15:46:17",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957407": [
        {
            "ioc_value": "b89a4327a54f933b7a1f8155354c21bea8df2c3e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:29",
            "last_seen_utc": "2026-10-09 15:46:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957408": [
        {
            "ioc_value": "8eb439edd96c03e46ba5c9751aa6a03f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:29",
            "last_seen_utc": "2026-10-09 15:46:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957409": [
        {
            "ioc_value": "7d72264319c996b8c3dabfb3ae01961f7c124471207bae849e85cea32c82c79a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-08 14:33:29",
            "last_seen_utc": "2026-10-09 15:46:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957410": [
        {
            "ioc_value": "b69d5b01a2ff6e2d058e16977677b5e586f93c83",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-08 14:33:29",
            "last_seen_utc": "2026-10-09 15:46:16",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957404": [
        {
            "ioc_value": "77eb6b1e2c9d9ee68bb2b8cf1e8612fd8a9b8932",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.mydoom",
            "malware_alias": "Novarg,Mimail",
            "malware_printable": "MyDoom",
            "first_seen_utc": "2026-10-08 14:33:28",
            "last_seen_utc": "2026-10-09 15:46:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957405": [
        {
            "ioc_value": "c0882cc19a0c5b9778ee44c00907a4e1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.mydoom",
            "malware_alias": "Novarg,Mimail",
            "malware_printable": "MyDoom",
            "first_seen_utc": "2026-10-08 14:33:28",
            "last_seen_utc": "2026-10-09 15:46:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957406": [
        {
            "ioc_value": "936a9be170eaac13ffd1432dd6e703dfbd478ce690a58e0a2a0c5bdb286a6a84",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:28",
            "last_seen_utc": "2026-10-09 15:46:15",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957402": [
        {
            "ioc_value": "5b1caeb928153142ec9b112a005d53c6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.masslogger",
            "malware_alias": null,
            "malware_printable": "MASS Logger",
            "first_seen_utc": "2026-10-08 14:33:27",
            "last_seen_utc": "2026-10-09 15:46:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957403": [
        {
            "ioc_value": "f3281793c4a06500ca92340714d5726733766f3f1e120fda2eaa64d060dab4ac",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.mydoom",
            "malware_alias": "Novarg,Mimail",
            "malware_printable": "MyDoom",
            "first_seen_utc": "2026-10-08 14:33:27",
            "last_seen_utc": "2026-10-09 15:46:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957399": [
        {
            "ioc_value": "899f8c35499817aa487210462eaf1e42",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.mydoom",
            "malware_alias": "Novarg,Mimail",
            "malware_printable": "MyDoom",
            "first_seen_utc": "2026-10-08 14:33:26",
            "last_seen_utc": "2026-10-09 15:46:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957400": [
        {
            "ioc_value": "9ed37a8cf3d0a86a6ac283c2976f58af63578ff93d9bd08ff923f95977c8e64f",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.masslogger",
            "malware_alias": null,
            "malware_printable": "MASS Logger",
            "first_seen_utc": "2026-10-08 14:33:26",
            "last_seen_utc": "2026-10-09 15:46:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957401": [
        {
            "ioc_value": "e9c62bb1dd931584b23fa4c1b178f27ec78fcc4c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.masslogger",
            "malware_alias": null,
            "malware_printable": "MASS Logger",
            "first_seen_utc": "2026-10-08 14:33:26",
            "last_seen_utc": "2026-10-09 15:46:14",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957396": [
        {
            "ioc_value": "9b33f0f6942d22efbfac413f3b3285f8",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-08 14:33:25",
            "last_seen_utc": "2026-10-09 15:46:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957397": [
        {
            "ioc_value": "3c46a3d6f83ce5fc37f328eb80e6cc4121cb41befacc54d2843d15a8a0395b94",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.mydoom",
            "malware_alias": "Novarg,Mimail",
            "malware_printable": "MyDoom",
            "first_seen_utc": "2026-10-08 14:33:25",
            "last_seen_utc": "2026-10-09 15:46:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957398": [
        {
            "ioc_value": "5d9c5afb0ca8406641269fd980e3a3086a818dc8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.mydoom",
            "malware_alias": "Novarg,Mimail",
            "malware_printable": "MyDoom",
            "first_seen_utc": "2026-10-08 14:33:25",
            "last_seen_utc": "2026-10-09 15:46:13",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957393": [
        {
            "ioc_value": "a4ad709d219448e605e0537d3fafa399",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:24",
            "last_seen_utc": "2026-10-09 15:46:11",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957394": [
        {
            "ioc_value": "354ed74cf297bdc4d920e3bb357fea7202856277501cbe914b1dfbe8813e841c",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-08 14:33:24",
            "last_seen_utc": "2026-10-09 15:46:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957395": [
        {
            "ioc_value": "d312493c19866f8c87ba59a3ceeb467f614568e8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-10-08 14:33:24",
            "last_seen_utc": "2026-10-09 15:46:12",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957390": [
        {
            "ioc_value": "5c9bc5f302bd0e2e31fbfefcd96d4a6a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-08 14:33:23",
            "last_seen_utc": "2026-10-09 15:46:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957391": [
        {
            "ioc_value": "7a9bffbf3a920d9b72d73b73cf09f3be5dadf025055f42b5dd12761ab7c8dd34",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:23",
            "last_seen_utc": "2026-10-09 15:46:11",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957392": [
        {
            "ioc_value": "8992765b3f9479fb14ef07e077459766566a6811",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:23",
            "last_seen_utc": "2026-10-09 15:46:11",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957387": [
        {
            "ioc_value": "88bd93c3462c1e219d6b64af47ab22fc",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-08 14:33:22",
            "last_seen_utc": "2026-10-09 15:46:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957388": [
        {
            "ioc_value": "217b221e5bcfad247ba6fa8f11809967a57d536a6d049c7200542cb8efe883c4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-08 14:33:22",
            "last_seen_utc": "2026-10-09 15:46:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957389": [
        {
            "ioc_value": "41e845c2b85a3b7fd8db67d25028dd904876e094",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-08 14:33:22",
            "last_seen_utc": "2026-10-09 15:46:10",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957384": [
        {
            "ioc_value": "a08d54b8d16c4a4a71eb1714e5025be0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:21",
            "last_seen_utc": "2026-10-09 15:46:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957385": [
        {
            "ioc_value": "680a01fc7667fe9589137b855256e60e391700f4063dd887d165a86d72c8c9ef",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-08 14:33:21",
            "last_seen_utc": "2026-10-09 15:46:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957386": [
        {
            "ioc_value": "c3103ab2f313ab8c70d4f0ac3beaf67e51e2f849",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-08 14:33:21",
            "last_seen_utc": "2026-10-09 15:46:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957382": [
        {
            "ioc_value": "461ba9a7d6b344421967b3c71630ec4796126b5f20bef32111447ac58e9b9202",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:20",
            "last_seen_utc": "2026-10-09 15:46:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957383": [
        {
            "ioc_value": "0703c26a5d36b9e85afa311909834650227821f0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:20",
            "last_seen_utc": "2026-10-09 15:46:09",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957379": [
        {
            "ioc_value": "365863cfdd112035bda3f239eeb69fe4239e8b28ae3fc5fd6ffaf2d3f2035894",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-08 14:33:19",
            "last_seen_utc": "2026-10-09 15:46:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957380": [
        {
            "ioc_value": "690de0f7a1e595b750aa1518b890b1cd08ca6dca",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-08 14:33:19",
            "last_seen_utc": "2026-10-09 15:46:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957381": [
        {
            "ioc_value": "45255bcad4c58e6549e52753ddb655ee",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.wannacryptor",
            "malware_alias": "Wana Decrypt0r,WannaCry,WannaCrypt,Wcry",
            "malware_printable": "WannaCryptor",
            "first_seen_utc": "2026-10-08 14:33:19",
            "last_seen_utc": "2026-10-09 15:46:08",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957378": [
        {
            "ioc_value": "2ae5ab42f2924330344e5dd45c5bf841",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:18",
            "last_seen_utc": "2026-10-09 15:46:07",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957375": [
        {
            "ioc_value": "a53d0903f4b158b1d1be8b9645a293af",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:17",
            "last_seen_utc": "2026-10-09 15:46:07",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957376": [
        {
            "ioc_value": "bcaa60dcc3369c42e9defb51c96939a1fb6ad9020faf1bf21b42c737c7cfb4eb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:17",
            "last_seen_utc": "2026-10-09 15:46:07",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957377": [
        {
            "ioc_value": "25034819db6e5e7930414f5c4edb273940447555",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:17",
            "last_seen_utc": "2026-10-09 15:46:07",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957371": [
        {
            "ioc_value": "c6f615bd8465fde10b96ea8c8206d40edc181145",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-10-08 14:33:16",
            "last_seen_utc": "2026-10-09 15:46:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957372": [
        {
            "ioc_value": "90d5acfb0c1245c23891a5c86c316f99",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-10-08 14:33:16",
            "last_seen_utc": "2026-10-09 15:46:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957373": [
        {
            "ioc_value": "a36cbacd3c6950de6319523835e895e8b35e32549c3a4673b3ead5215ad0d3e8",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:16",
            "last_seen_utc": "2026-10-09 15:46:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957374": [
        {
            "ioc_value": "9dd1bd931d87ae8acece9f7e0c7f3187535f7312",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-10-08 14:33:16",
            "last_seen_utc": "2026-10-09 15:46:06",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957368": [
        {
            "ioc_value": "f3be5de6f583f9e22b748a36fb25f679f2830874",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:15",
            "last_seen_utc": "2026-10-09 15:46:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957369": [
        {
            "ioc_value": "c8c2cf8b54a8b34a64d9629b2546314b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:15",
            "last_seen_utc": "2026-10-09 15:46:03",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957370": [
        {
            "ioc_value": "da4426aed3b3d6b238fdd1fff82aa26de19975d292a64e429543556fb1450179",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.phantom_stealer",
            "malware_alias": null,
            "malware_printable": "Phantom Stealer",
            "first_seen_utc": "2026-10-08 14:33:15",
            "last_seen_utc": "2026-10-09 15:46:05",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957365": [
        {
            "ioc_value": "dee795ea89e6ebddf3544cf9b67cb91c5c98c281",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-08 14:33:14",
            "last_seen_utc": "2026-10-09 15:46:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957366": [
        {
            "ioc_value": "88c303b6a584e5f22c771fe8bbabdf0c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-08 14:33:14",
            "last_seen_utc": "2026-10-09 15:46:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957367": [
        {
            "ioc_value": "41a483806de558a54f5e294d7909b79f7e57fd89a47fde2afb8118188865e126",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:14",
            "last_seen_utc": "2026-10-09 15:46:02",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957361": [
        {
            "ioc_value": "06debf2c915467c52668c837639d4ed6044310e8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:13",
            "last_seen_utc": "2026-10-09 15:46:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957362": [
        {
            "ioc_value": "200fb6726d73209a82e1d3d846c6b684",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:13",
            "last_seen_utc": "2026-10-09 15:46:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957364": [
        {
            "ioc_value": "38907cfc64ad45bcd1887ac6a6aa363ef5926c2e6bf2969aa92eeeddcd27a532",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-10-08 14:33:13",
            "last_seen_utc": "2026-10-09 15:46:01",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957359": [
        {
            "ioc_value": "af720cb19686c51d8c68414bacba8dbe",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-10-08 14:33:12",
            "last_seen_utc": "2026-10-09 15:45:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957360": [
        {
            "ioc_value": "777021046368ae3127d81fb3dec07bce6dd25d45171a035270e9b22d8a8312ff",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.stealler",
            "malware_alias": null,
            "malware_printable": "stealler",
            "first_seen_utc": "2026-10-08 14:33:12",
            "last_seen_utc": "2026-10-09 15:46:00",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957356": [
        {
            "ioc_value": "04f690ebbefd721c72f79d60dc6dc72b",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-10-08 14:33:11",
            "last_seen_utc": "2026-10-09 15:45:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957357": [
        {
            "ioc_value": "bc79eb0bdea5e7e087aaa68a20f43cec3456654be2cd60be14ffc17f8d060094",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-10-08 14:33:11",
            "last_seen_utc": "2026-10-09 15:45:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957358": [
        {
            "ioc_value": "2b69bb40a7e2757286713be9a6ac38955871e63c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-10-08 14:33:11",
            "last_seen_utc": "2026-10-09 15:45:59",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957353": [
        {
            "ioc_value": "0a7f8a3e8e5c4e70f7ec2863a70c95e0",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-08 14:33:10",
            "last_seen_utc": "2026-10-09 15:45:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957354": [
        {
            "ioc_value": "abd9d912407f5336088a5b5394178df2994377f6738651bf37bc0d6976d0c861",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-10-08 14:33:10",
            "last_seen_utc": "2026-10-09 15:45:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957355": [
        {
            "ioc_value": "782e3585bc0f1566253c1a2e35fbfc4cbae62e07",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.njrat",
            "malware_alias": "Bladabindi,Lime-Worm",
            "malware_printable": "NjRAT",
            "first_seen_utc": "2026-10-08 14:33:10",
            "last_seen_utc": "2026-10-09 15:45:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957351": [
        {
            "ioc_value": "9bf6e7fd924aa4aff92bb5db0705d5300e7a6e199c73be2fc9bdecb9819194fe",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-08 14:33:09",
            "last_seen_utc": "2026-10-09 15:45:57",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957352": [
        {
            "ioc_value": "3e6bcfc6a14a1e60459cce6625b6354ce5428493",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-10-08 14:33:09",
            "last_seen_utc": "2026-10-09 15:45:58",
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1957334": [
        {
            "ioc_value": "https://172.235.182.6",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:06:14",
            "last_seen_utc": "2026-10-09 11:59:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0086075e3f7c97c9ab04a1a2cd48e78b,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957335": [
        {
            "ioc_value": "https://172.105.64.167",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 14:06:14",
            "last_seen_utc": "2026-10-09 12:01:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "9907f3712d269b106ae1de2f415a7914,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957331": [
        {
            "ioc_value": "49.235.158.141:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-08 13:46:12",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957330": [
        {
            "ioc_value": "43.138.221.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-08 13:46:08",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957310": [
        {
            "ioc_value": "63d5297ab9ccc40d45877940e18d5403e26914f1d71b59fb973f667d9095df54",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 13:40:26",
            "last_seen_utc": "2026-10-09 15:46:18",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "d52f85,dropped-by-Amadey,exe,upx,Vidar",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1957248": [
        {
            "ioc_value": "trinea.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:55",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957249": [
        {
            "ioc_value": "verbum.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:55",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957251": [
        {
            "ioc_value": "voiceartcenter.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:55",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957252": [
        {
            "ioc_value": "waiwaio.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:55",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957253": [
        {
            "ioc_value": "weltransim.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:55",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957257": [
        {
            "ioc_value": "zavlahymajer.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:55",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957230": [
        {
            "ioc_value": "rkpelet.sk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957231": [
        {
            "ioc_value": "roaminginrome.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957232": [
        {
            "ioc_value": "rsee.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957233": [
        {
            "ioc_value": "ryrimportadora.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957234": [
        {
            "ioc_value": "salesforce-us.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957236": [
        {
            "ioc_value": "serviofood.dk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957237": [
        {
            "ioc_value": "sonquimet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957238": [
        {
            "ioc_value": "spicegirlsingredients.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957239": [
        {
            "ioc_value": "steconf.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957240": [
        {
            "ioc_value": "steviamadblend.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957241": [
        {
            "ioc_value": "t-m-w.at",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957242": [
        {
            "ioc_value": "teachmodellearn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957243": [
        {
            "ioc_value": "thelivinglives.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957244": [
        {
            "ioc_value": "thermal-fabrics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957245": [
        {
            "ioc_value": "thewellnessinsights.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957246": [
        {
            "ioc_value": "thrivesyte.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957247": [
        {
            "ioc_value": "toutvabienbien.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:54",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957209": [
        {
            "ioc_value": "nyankids.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957210": [
        {
            "ioc_value": "oniramen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957211": [
        {
            "ioc_value": "optik-missbach.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957212": [
        {
            "ioc_value": "oracle-epc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957213": [
        {
            "ioc_value": "orbitinstitutes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957214": [
        {
            "ioc_value": "ovalofficeclub.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957215": [
        {
            "ioc_value": "perf.trinea.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957216": [
        {
            "ioc_value": "pescobar.neagest.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957217": [
        {
            "ioc_value": "platino.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957218": [
        {
            "ioc_value": "pmfloridaelectric.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957219": [
        {
            "ioc_value": "proditech.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957221": [
        {
            "ioc_value": "promotorinmobiliario.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957222": [
        {
            "ioc_value": "quincy.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957225": [
        {
            "ioc_value": "rentaboatkrk.hr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957226": [
        {
            "ioc_value": "reservadosipescuiaba.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957227": [
        {
            "ioc_value": "restrofranchise.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957228": [
        {
            "ioc_value": "rgdallas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:53",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957187": [
        {
            "ioc_value": "loseyourselfinlove.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957188": [
        {
            "ioc_value": "macph.dk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957190": [
        {
            "ioc_value": "mariusbroeders.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957191": [
        {
            "ioc_value": "maxocean-marketing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957192": [
        {
            "ioc_value": "mcdanielwoolf.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957194": [
        {
            "ioc_value": "metalljahn.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957196": [
        {
            "ioc_value": "mielenz-stahlbau.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957197": [
        {
            "ioc_value": "mikagroep.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957199": [
        {
            "ioc_value": "mm-mmm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957200": [
        {
            "ioc_value": "moyula.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957201": [
        {
            "ioc_value": "myswapscollection.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957202": [
        {
            "ioc_value": "n-sommer.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957203": [
        {
            "ioc_value": "ncux.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957204": [
        {
            "ioc_value": "nemesvitakilato.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957206": [
        {
            "ioc_value": "ngobrolfootball.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957207": [
        {
            "ioc_value": "noviscoalindonesia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:52",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957171": [
        {
            "ioc_value": "inmoarc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957172": [
        {
            "ioc_value": "iowapeernetwork.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957173": [
        {
            "ioc_value": "iplexus.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957174": [
        {
            "ioc_value": "isabellaisjakt.se",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957175": [
        {
            "ioc_value": "jk-products.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957176": [
        {
            "ioc_value": "kebap-koenig.at",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957177": [
        {
            "ioc_value": "kgv-sommerheim.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957178": [
        {
            "ioc_value": "kindercan.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957179": [
        {
            "ioc_value": "kirkagackavun.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957180": [
        {
            "ioc_value": "korowater.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957181": [
        {
            "ioc_value": "labpetcuritiba.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957182": [
        {
            "ioc_value": "laturbacantiano.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957183": [
        {
            "ioc_value": "levnaomi.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957184": [
        {
            "ioc_value": "limitlessroofingsolutions.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957186": [
        {
            "ioc_value": "lofty-fabrics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:51",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957160": [
        {
            "ioc_value": "fotografstudyosu.com.tr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957161": [
        {
            "ioc_value": "frankpulice.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957162": [
        {
            "ioc_value": "franksdigitaltv.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957163": [
        {
            "ioc_value": "fratelliseveso.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957164": [
        {
            "ioc_value": "fudepi.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957166": [
        {
            "ioc_value": "gardenabeels.be",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957167": [
        {
            "ioc_value": "gruppomassucci.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957168": [
        {
            "ioc_value": "happydays-toti.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957169": [
        {
            "ioc_value": "hartransplantasjon.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957170": [
        {
            "ioc_value": "hotelimmagine.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:50",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957145": [
        {
            "ioc_value": "carbzaar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957146": [
        {
            "ioc_value": "chatavalkov.sk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957147": [
        {
            "ioc_value": "cierre3000.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957148": [
        {
            "ioc_value": "cupcon.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957149": [
        {
            "ioc_value": "david-chappell.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957150": [
        {
            "ioc_value": "dcanales.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957151": [
        {
            "ioc_value": "dramboat.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957152": [
        {
            "ioc_value": "e-bikroy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957153": [
        {
            "ioc_value": "elitmuhendislik.com.tr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957154": [
        {
            "ioc_value": "enniodifrancesco.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957155": [
        {
            "ioc_value": "eosusa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957157": [
        {
            "ioc_value": "exceldesignoutfits.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:49",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957134": [
        {
            "ioc_value": "99homedecor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957135": [
        {
            "ioc_value": "aibestuse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957137": [
        {
            "ioc_value": "amitypackaging.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957138": [
        {
            "ioc_value": "arthare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957139": [
        {
            "ioc_value": "asthhc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957140": [
        {
            "ioc_value": "bergrestaurant-polite.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957141": [
        {
            "ioc_value": "bindslev-museum.dk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957142": [
        {
            "ioc_value": "bloemenop12.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957143": [
        {
            "ioc_value": "bubr.ac.th",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-08 12:33:48",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1957121": [
        {
            "ioc_value": "europevoyages-madagascartours.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957122": [
        {
            "ioc_value": "iaro.org.nz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957124": [
        {
            "ioc_value": "kanasacademy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:20",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957118": [
        {
            "ioc_value": "arnidecor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:19",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957120": [
        {
            "ioc_value": "bulimester.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:19",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957114": [
        {
            "ioc_value": "chogianphoi.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:18",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957115": [
        {
            "ioc_value": "drmitachowdhury.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:18",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957113": [
        {
            "ioc_value": "comprojoiasrj.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:14:17",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957108": [
        {
            "ioc_value": "196.77.102.208:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 12:05:04",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957107": [
        {
            "ioc_value": "intercobrancas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957100": [
        {
            "ioc_value": "cortimet.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:15",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957101": [
        {
            "ioc_value": "baferequipos.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:15",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957102": [
        {
            "ioc_value": "davidov-property.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:15",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957103": [
        {
            "ioc_value": "jaduanas.pe",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:15",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957096": [
        {
            "ioc_value": "cmr.rs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:14",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957097": [
        {
            "ioc_value": "keypainting.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:14",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957098": [
        {
            "ioc_value": "2growvn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:14",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957099": [
        {
            "ioc_value": "inmes.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:14",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957092": [
        {
            "ioc_value": "irqtg.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:13",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957094": [
        {
            "ioc_value": "drahmedadel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:13",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957095": [
        {
            "ioc_value": "fsglobaladvisory.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:13",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957090": [
        {
            "ioc_value": "electrozirveofficial.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:12",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957091": [
        {
            "ioc_value": "audricandsofiya.wedding",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 12:04:12",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957072": [
        {
            "ioc_value": "95.211.44.207:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-08 10:45:56",
            "last_seen_utc": "2026-10-11 08:25:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957073": [
        {
            "ioc_value": "45.128.234.124:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-08 10:45:56",
            "last_seen_utc": "2026-10-11 04:52:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,cveil,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1957068": [
        {
            "ioc_value": "91.215.85.140:44113",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-08 09:45:38",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957067": [
        {
            "ioc_value": "78.40.209.158:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:45:29",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957065": [
        {
            "ioc_value": "67.86.75.244:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:45:26",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957066": [
        {
            "ioc_value": "67.86.75.244:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:45:26",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957064": [
        {
            "ioc_value": "66.29.151.122:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-08 09:45:25",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957062": [
        {
            "ioc_value": "46.246.12.2:5064",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:45:15",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957063": [
        {
            "ioc_value": "46.246.12.2:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:45:15",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957059": [
        {
            "ioc_value": "217.20.120.84:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-08 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957060": [
        {
            "ioc_value": "217.60.102.37:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957061": [
        {
            "ioc_value": "217.60.102.37:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957058": [
        {
            "ioc_value": "196.77.102.208:5001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:44:14",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957057": [
        {
            "ioc_value": "162.254.37.211:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 09:43:46",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957056": [
        {
            "ioc_value": "157.20.182.15:1339",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:43:42",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957055": [
        {
            "ioc_value": "157.20.182.14:1339",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:43:41",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957054": [
        {
            "ioc_value": "143.110.219.27:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-10-08 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957053": [
        {
            "ioc_value": "136.64.155.203:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 09:43:25",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957052": [
        {
            "ioc_value": "130.61.99.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 09:43:23",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957051": [
        {
            "ioc_value": "128.90.105.90:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:43:20",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957050": [
        {
            "ioc_value": "104.254.90.122:40452",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:43:13",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957049": [
        {
            "ioc_value": "104.243.248.63:403",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-08 09:43:12",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1957026": [
        {
            "ioc_value": "102.117.161.148:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 08:05:06",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1957003": [
        {
            "ioc_value": "74.241.250.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-08 06:05:06",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1956789": [
        {
            "ioc_value": "https://stellaspicy.org/mining/wallet.txt",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 05:34:33",
            "last_seen_utc": "2026-10-09 19:25:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "miner,monero,runelure",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1956790": [
        {
            "ioc_value": "https://stellaspicy.org/mining/pool.txt",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-08 05:34:33",
            "last_seen_utc": "2026-10-09 19:25:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "miner,monero,runelure",
            "anonymous": 0,
            "reporter": "rc4"
        }
    ],
    "1956715": [
        {
            "ioc_value": "198.135.49.110:4489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-08 05:34:31",
            "last_seen_utc": "2026-10-09 12:10:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,ONETOUCH,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956826": [
        {
            "ioc_value": "178.16.53.59:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-08 05:34:18",
            "last_seen_utc": "2026-10-11 05:09:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956862": [
        {
            "ioc_value": "152.42.197.255:8632",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-08 05:34:09",
            "last_seen_utc": "2026-10-11 08:37:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "9449243aad9ab69cb6593789b788422f,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956882": [
        {
            "ioc_value": "https://gy.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 05:34:00",
            "last_seen_utc": "2026-10-11 07:32:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5259d515f2c8cc65b29ec1b9814990b7,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956892": [
        {
            "ioc_value": "45.128.234.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-08 05:33:59",
            "last_seen_utc": "2026-10-11 05:04:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,cveil,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956936": [
        {
            "ioc_value": "https://kl.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 05:33:50",
            "last_seen_utc": "2026-10-11 07:28:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2f3c6fb2d82ed66e2e45208cd1c7edd1,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956997": [
        {
            "ioc_value": "https://gy.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-08 05:33:49",
            "last_seen_utc": "2026-10-10 18:18:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5259d515f2c8cc65b29ec1b9814990b7,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956982": [
        {
            "ioc_value": "rramadasmakeovers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 05:23:48",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1956947": [
        {
            "ioc_value": "ridge-goalmduix.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 05:23:01",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1956945": [
        {
            "ioc_value": "kraeldskiynlucid.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 05:23:00",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1956946": [
        {
            "ioc_value": "krioldflaeara-willow.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-08 05:23:00",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1956926": [
        {
            "ioc_value": "165.22.244.100:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-08 02:47:40",
            "last_seen_utc": "2026-10-09 22:07:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956925": [
        {
            "ioc_value": "138.68.135.200:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-08 02:47:39",
            "last_seen_utc": "2026-10-11 09:10:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956913": [
        {
            "ioc_value": "164.92.243.20:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-08 01:46:01",
            "last_seen_utc": "2026-10-10 09:20:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956910": [
        {
            "ioc_value": "privatejetfuel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-08 01:26:33",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1956718": [
        {
            "ioc_value": "mtclogistic.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-07 19:58:19",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1956714": [
        {
            "ioc_value": "95.179.183.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-10-07 19:45:35",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956713": [
        {
            "ioc_value": "93.152.214.174:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:45:31",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956712": [
        {
            "ioc_value": "85.202.161.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-07 19:45:26",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956711": [
        {
            "ioc_value": "84.200.91.170:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:45:24",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956709": [
        {
            "ioc_value": "80.76.49.209:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:45:22",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956710": [
        {
            "ioc_value": "80.94.92.180:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-07 19:45:22",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956708": [
        {
            "ioc_value": "80.76.49.104:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:45:21",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956707": [
        {
            "ioc_value": "64.89.160.127:2021",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 19:45:16",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956706": [
        {
            "ioc_value": "46.246.84.5:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 19:45:08",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956705": [
        {
            "ioc_value": "45.88.91.164:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:45:06",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956704": [
        {
            "ioc_value": "23.94.212.126:41337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-07 19:44:44",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956703": [
        {
            "ioc_value": "217.60.103.15:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:44:37",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956701": [
        {
            "ioc_value": "207.56.3.27:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956702": [
        {
            "ioc_value": "207.56.3.56:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956700": [
        {
            "ioc_value": "196.251.121.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-10-07 19:44:10",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956699": [
        {
            "ioc_value": "186.169.33.116:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 19:43:59",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956698": [
        {
            "ioc_value": "185.212.129.89:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-07 19:43:56",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956697": [
        {
            "ioc_value": "18.176.225.124:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-10-07 19:43:52",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956696": [
        {
            "ioc_value": "176.96.137.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:50",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956695": [
        {
            "ioc_value": "172.105.110.70:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-07 19:43:46",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956692": [
        {
            "ioc_value": "160.119.76.118:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956693": [
        {
            "ioc_value": "160.119.76.118:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956694": [
        {
            "ioc_value": "160.119.76.118:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956691": [
        {
            "ioc_value": "157.20.182.14:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956690": [
        {
            "ioc_value": "157.137.215.66:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-07 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956689": [
        {
            "ioc_value": "130.61.99.190:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-07 19:43:22",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956688": [
        {
            "ioc_value": "128.90.105.180:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 19:43:18",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956687": [
        {
            "ioc_value": "103.181.177.61:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956686": [
        {
            "ioc_value": "102.220.161.177:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:06",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956685": [
        {
            "ioc_value": "102.220.161.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 19:43:05",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956632": [
        {
            "ioc_value": "178.16.53.56:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 17:40:53",
            "last_seen_utc": "2026-10-11 09:19:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956633": [
        {
            "ioc_value": "178.16.53.59:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 17:40:53",
            "last_seen_utc": "2026-10-11 09:50:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956634": [
        {
            "ioc_value": "178.16.53.68:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 17:40:53",
            "last_seen_utc": "2026-10-11 09:19:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956635": [
        {
            "ioc_value": "178.16.53.76:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 17:40:53",
            "last_seen_utc": "2026-10-11 09:18:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956630": [
        {
            "ioc_value": "birch-koix-7keeb.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-07 17:34:23",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1956622": [
        {
            "ioc_value": "https://xs.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-07 16:58:53",
            "last_seen_utc": "2026-10-11 07:42:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1956621": [
        {
            "ioc_value": "89.32.41.43:15987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 16:57:30",
            "last_seen_utc": "2026-10-09 14:57:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956309": [
        {
            "ioc_value": "138.197.128.142:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 14:28:47",
            "last_seen_utc": "2026-10-10 14:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956310": [
        {
            "ioc_value": "159.89.196.255:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 14:28:47",
            "last_seen_utc": "2026-10-10 14:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956311": [
        {
            "ioc_value": "165.245.252.125:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 14:28:47",
            "last_seen_utc": "2026-10-10 14:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956312": [
        {
            "ioc_value": "188.166.229.242:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 14:28:47",
            "last_seen_utc": "2026-10-10 14:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956313": [
        {
            "ioc_value": "201.79.48.108:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 14:28:47",
            "last_seen_utc": "2026-10-10 14:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956314": [
        {
            "ioc_value": "207.154.219.20:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 14:28:47",
            "last_seen_utc": "2026-10-10 22:36:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956304": [
        {
            "ioc_value": "https://xs.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-07 14:27:33",
            "last_seen_utc": "2026-10-11 07:21:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b98dd86b169ec45dd28e99dcad12402a,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956290": [
        {
            "ioc_value": "102.117.168.65:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-07 13:05:05",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1956272": [
        {
            "ioc_value": "103.83.86.40:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-07 11:44:51",
            "last_seen_utc": "2026-10-11 05:31:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956271": [
        {
            "ioc_value": "https://95.182.97.240",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-07 11:08:02",
            "last_seen_utc": "2026-10-11 09:49:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "300d903d05d62a85efd0ca8bd247c97e,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956223": [
        {
            "ioc_value": "15.204.253.8:5621",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-07 10:38:21",
            "last_seen_utc": "2026-10-11 09:49:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5a4378fb90db39f09c7b18d1f314e645,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956226": [
        {
            "ioc_value": "https://fo.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-07 10:38:20",
            "last_seen_utc": "2026-10-11 02:29:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0db1ad10080756ea9ff93c3d332165e4,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956269": [
        {
            "ioc_value": "134.122.22.105:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 10:38:14",
            "last_seen_utc": "2026-10-09 15:52:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956222": [
        {
            "ioc_value": "91.92.41.66:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:45:48",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956221": [
        {
            "ioc_value": "52.246.183.133:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-07 09:45:27",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956220": [
        {
            "ioc_value": "46.246.6.8:5500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-07 09:45:22",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956219": [
        {
            "ioc_value": "46.246.12.6:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 09:45:21",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956218": [
        {
            "ioc_value": "23.92.20.189:8315",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-10-07 09:44:52",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956217": [
        {
            "ioc_value": "217.60.195.46:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:48",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956216": [
        {
            "ioc_value": "216.227.218.4:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-07 09:44:44",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956211": [
        {
            "ioc_value": "202.95.14.49:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:22",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956212": [
        {
            "ioc_value": "202.95.14.49:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:22",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956213": [
        {
            "ioc_value": "202.95.14.65:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:22",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956214": [
        {
            "ioc_value": "202.95.14.80:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:22",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956215": [
        {
            "ioc_value": "202.95.14.80:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:22",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956210": [
        {
            "ioc_value": "202.146.222.156:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:21",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956209": [
        {
            "ioc_value": "192.253.229.23:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:44:11",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956208": [
        {
            "ioc_value": "192.162.199.186:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 09:44:09",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956207": [
        {
            "ioc_value": "172.94.46.114:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 09:43:54",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956206": [
        {
            "ioc_value": "171.111.194.207:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-07 09:43:51",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956205": [
        {
            "ioc_value": "161.35.58.0:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-10-07 09:43:47",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956204": [
        {
            "ioc_value": "152.53.22.243:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-07 09:43:37",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956201": [
        {
            "ioc_value": "150.241.226.177:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956202": [
        {
            "ioc_value": "150.241.226.177:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956203": [
        {
            "ioc_value": "150.241.226.177:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956200": [
        {
            "ioc_value": "144.79.249.51:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 09:43:31",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956199": [
        {
            "ioc_value": "143.246.223.145:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:43:30",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956198": [
        {
            "ioc_value": "136.0.82.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:43:26",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956197": [
        {
            "ioc_value": "128.90.102.158:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-07 09:43:20",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956196": [
        {
            "ioc_value": "103.57.250.246:9015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-07 09:43:09",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956195": [
        {
            "ioc_value": "103.195.103.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-07 09:43:08",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956191": [
        {
            "ioc_value": "checkyoubrowse.codes",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-07 09:25:27",
            "last_seen_utc": "2026-10-09 15:19:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1956174": [
        {
            "ioc_value": "46.101.164.65:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-07 08:50:19",
            "last_seen_utc": "2026-10-09 15:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956180": [
        {
            "ioc_value": "130.94.1.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-07 08:35:25",
            "last_seen_utc": "2026-10-11 08:50:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956181": [
        {
            "ioc_value": "130.94.32.14:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-07 08:35:25",
            "last_seen_utc": "2026-10-11 08:50:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956186": [
        {
            "ioc_value": "38.60.136.140:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-07 08:35:25",
            "last_seen_utc": "2026-10-11 08:50:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956167": [
        {
            "ioc_value": "31.56.19.72:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 07:26:02",
            "last_seen_utc": "2026-10-11 07:35:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956168": [
        {
            "ioc_value": "31.56.19.73:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 07:26:02",
            "last_seen_utc": "2026-10-11 07:35:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956169": [
        {
            "ioc_value": "31.56.19.74:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 07:26:02",
            "last_seen_utc": "2026-10-11 07:35:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956165": [
        {
            "ioc_value": "31.56.19.75:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 07:22:50",
            "last_seen_utc": "2026-10-11 07:29:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956166": [
        {
            "ioc_value": "89.32.41.43:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 07:22:50",
            "last_seen_utc": "2026-10-11 07:29:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956160": [
        {
            "ioc_value": "31.56.19.70:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 06:57:26",
            "last_seen_utc": "2026-10-11 07:07:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956144": [
        {
            "ioc_value": "217.60.103.15:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-07 06:05:04",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1955703": [
        {
            "ioc_value": "45.55.202.73:9932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-07 04:37:50",
            "last_seen_utc": "2026-10-11 09:41:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5a4378fb90db39f09c7b18d1f314e645,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956121": [
        {
            "ioc_value": "194.116.236.83:15800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-07 04:37:32",
            "last_seen_utc": "2026-10-11 00:09:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956134": [
        {
            "ioc_value": "https://fo.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-07 04:37:31",
            "last_seen_utc": "2026-10-11 07:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0db1ad10080756ea9ff93c3d332165e4,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1956130": [
        {
            "ioc_value": "129.204.55.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-07 03:46:09",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956124": [
        {
            "ioc_value": "89.32.41.111:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:22",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956125": [
        {
            "ioc_value": "89.32.41.114:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:22",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956126": [
        {
            "ioc_value": "89.32.41.117:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:22",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956127": [
        {
            "ioc_value": "89.32.41.128:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:22",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956128": [
        {
            "ioc_value": "89.32.41.146:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:22",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956122": [
        {
            "ioc_value": "89.32.41.108:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:21",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956123": [
        {
            "ioc_value": "89.32.41.109:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:45:21",
            "last_seen_utc": "2026-10-11 04:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956117": [
        {
            "ioc_value": "45.79.198.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-07 03:05:07",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1956114": [
        {
            "ioc_value": "89.32.41.59:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-07 03:04:05",
            "last_seen_utc": "2026-10-11 03:13:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956098": [
        {
            "ioc_value": "http://91.92.241.109/78297b2fa2ac49ca8eb0.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-10-07 01:45:22",
            "last_seen_utc": "2026-10-11 09:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ffce7a3896c7e9e8172737d45c1eaed7f62b0a09b65ce22c5eeff9f25b7ace9d/",
            "tags": "stealc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956051": [
        {
            "ioc_value": "89.32.41.19:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-06 21:19:56",
            "last_seen_utc": "2026-10-10 21:35:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956027": [
        {
            "ioc_value": "130.94.16.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 20:17:47",
            "last_seen_utc": "2026-10-10 20:23:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956028": [
        {
            "ioc_value": "130.94.77.120:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 20:17:47",
            "last_seen_utc": "2026-10-10 20:23:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956029": [
        {
            "ioc_value": "38.60.199.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 20:17:47",
            "last_seen_utc": "2026-10-10 20:23:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1956014": [
        {
            "ioc_value": "47.94.56.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-06 19:46:07",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956013": [
        {
            "ioc_value": "5.180.42.176:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-06 19:45:16",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956012": [
        {
            "ioc_value": "45.76.161.231:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-06 19:45:11",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956011": [
        {
            "ioc_value": "217.165.57.21:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 19:44:41",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956010": [
        {
            "ioc_value": "194.59.31.71:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-06 19:44:12",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956009": [
        {
            "ioc_value": "192.162.199.186:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 19:44:06",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956008": [
        {
            "ioc_value": "170.238.45.33:7222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-06 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956007": [
        {
            "ioc_value": "135.136.148.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-06 19:43:24",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956006": [
        {
            "ioc_value": "104.249.10.19:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-06 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956005": [
        {
            "ioc_value": "104.243.248.63:411",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 19:43:11",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1956004": [
        {
            "ioc_value": "104.194.155.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-06 19:43:10",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1955698": [
        {
            "ioc_value": "89.32.41.19:15987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-06 16:57:12",
            "last_seen_utc": "2026-10-10 13:27:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1955687": [
        {
            "ioc_value": "https://hi.3toto.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-06 16:18:33",
            "last_seen_utc": "2026-10-10 14:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b98dd86b169ec45dd28e99dcad12402a,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1955692": [
        {
            "ioc_value": "89.32.41.49:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-06 16:03:36",
            "last_seen_utc": "2026-10-10 16:08:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1955677": [
        {
            "ioc_value": "https://hi.333vip.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-06 15:21:44",
            "last_seen_utc": "2026-10-11 07:45:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b98dd86b169ec45dd28e99dcad12402a,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1955683": [
        {
            "ioc_value": "102.220.163.130:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 15:21:43",
            "last_seen_utc": "2026-10-11 05:34:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,MWSCL,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1955684": [
        {
            "ioc_value": "91.92.242.19:7193",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.potassium",
            "malware_alias": null,
            "malware_printable": "Potassium",
            "first_seen_utc": "2026-10-06 15:17:46",
            "last_seen_utc": "2026-10-10 15:28:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/potassium",
            "tags": "botnet,ddos,mirai,potassium,woof",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1955621": [
        {
            "ioc_value": "wsaindia.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-06 13:53:37",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1955526": [
        {
            "ioc_value": "totalplumbingfl.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-06 13:53:03",
            "last_seen_utc": "2026-10-09 15:20:02",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1955287": [
        {
            "ioc_value": "profitfarmers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-06 13:51:29",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1955030": [
        {
            "ioc_value": "infinitymarine.co.th",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-06 13:49:51",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1954996": [
        {
            "ioc_value": "giovannibataloni.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-06 13:49:11",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1954738": [
        {
            "ioc_value": "andrewodellmusic.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-06 13:46:50",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1954707": [
        {
            "ioc_value": "45.227.253.132:32775",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-06 13:45:58",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954706": [
        {
            "ioc_value": "117.158.148.164:65535",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-06 13:45:46",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954701": [
        {
            "ioc_value": "84.32.41.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 13:23:37",
            "last_seen_utc": "2026-10-11 08:47:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954691": [
        {
            "ioc_value": "coral-vale-grialdkeon.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-06 13:14:59",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1954643": [
        {
            "ioc_value": "194.116.236.83:15700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 12:29:45",
            "last_seen_utc": "2026-10-11 05:10:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954674": [
        {
            "ioc_value": "194.116.236.83:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 12:29:17",
            "last_seen_utc": "2026-10-11 00:06:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954614": [
        {
            "ioc_value": "https://wruser.org/sa1at/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-06 11:18:14",
            "last_seen_utc": "2026-10-11 03:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "salatstealer",
            "anonymous": 0,
            "reporter": "whenyoufind"
        }
    ],
    "1954615": [
        {
            "ioc_value": "https://wruser.org:992/sa1at/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-10-06 11:18:13",
            "last_seen_utc": "2026-10-11 03:48:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "salatstealer",
            "anonymous": 0,
            "reporter": "whenyoufind"
        }
    ],
    "1954592": [
        {
            "ioc_value": "155.103.71.210:55280",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 10:38:03",
            "last_seen_utc": "2026-10-11 09:27:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Oct-06-2026 Exploit,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954591": [
        {
            "ioc_value": "138.68.101.133:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 10:02:04",
            "last_seen_utc": "2026-10-11 03:04:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954590": [
        {
            "ioc_value": "188.227.14.105:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-06 09:45:51",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954589": [
        {
            "ioc_value": "5.152.222.114:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-06 09:45:09",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954587": [
        {
            "ioc_value": "46.246.14.5:5064",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 09:45:07",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954588": [
        {
            "ioc_value": "46.246.4.26:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-06 09:45:07",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954586": [
        {
            "ioc_value": "195.26.249.124:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-06 09:44:10",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954585": [
        {
            "ioc_value": "192.162.199.186:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 09:44:02",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954584": [
        {
            "ioc_value": "130.110.5.114:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-10-06 09:43:21",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954583": [
        {
            "ioc_value": "128.90.112.16:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 09:43:19",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954582": [
        {
            "ioc_value": "104.243.248.63:406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-06 09:43:11",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1954494": [
        {
            "ioc_value": "172.111.137.69:65070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 08:41:21",
            "last_seen_utc": "2026-10-11 08:43:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Oct-1-2026,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954491": [
        {
            "ioc_value": "217.60.242.27:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 08:27:52",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954492": [
        {
            "ioc_value": "64.89.160.50:1414",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-06 08:27:52",
            "last_seen_utc": "2026-10-11 04:59:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Sideload",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954478": [
        {
            "ioc_value": "64.227.35.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-06 08:05:04",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1954362": [
        {
            "ioc_value": "159.89.95.185:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 07:29:55",
            "last_seen_utc": "2026-10-11 05:12:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954335": [
        {
            "ioc_value": "rovgruien.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-06 05:52:51",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1954329": [
        {
            "ioc_value": "176.97.114.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 05:52:13",
            "last_seen_utc": "2026-10-10 06:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1954330": [
        {
            "ioc_value": "176.97.114.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 05:52:12",
            "last_seen_utc": "2026-10-10 06:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1954331": [
        {
            "ioc_value": "176.97.114.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 05:52:11",
            "last_seen_utc": "2026-10-10 06:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1954332": [
        {
            "ioc_value": "176.97.114.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 05:52:11",
            "last_seen_utc": "2026-10-10 06:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1954333": [
        {
            "ioc_value": "176.97.114.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 05:52:10",
            "last_seen_utc": "2026-10-10 06:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1954334": [
        {
            "ioc_value": "176.97.114.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-06 05:52:09",
            "last_seen_utc": "2026-10-10 06:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953319": [
        {
            "ioc_value": "https://fu.333pwk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-06 05:28:13",
            "last_seen_utc": "2026-10-11 07:33:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b98dd86b169ec45dd28e99dcad12402a,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1953342": [
        {
            "ioc_value": "https://fu.396zk.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-06 05:28:12",
            "last_seen_utc": "2026-10-11 07:34:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "18639d8e3c129270e4d9f4328b3819a1,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1953344": [
        {
            "ioc_value": "134.122.22.105:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:11",
            "last_seen_utc": "2026-10-11 09:28:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953363": [
        {
            "ioc_value": "138.68.101.133:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:11",
            "last_seen_utc": "2026-10-11 09:27:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953364": [
        {
            "ioc_value": "139.59.101.166:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:10",
            "last_seen_utc": "2026-10-11 09:27:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953366": [
        {
            "ioc_value": "165.22.244.100:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:08",
            "last_seen_utc": "2026-10-11 09:27:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953365": [
        {
            "ioc_value": "159.89.95.185:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:07",
            "last_seen_utc": "2026-10-11 09:28:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953367": [
        {
            "ioc_value": "46.101.164.65:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:06",
            "last_seen_utc": "2026-10-11 09:28:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1953539": [
        {
            "ioc_value": "139.59.101.166:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:28:04",
            "last_seen_utc": "2026-10-10 22:11:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1953542": [
        {
            "ioc_value": "134.122.22.105:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:27:59",
            "last_seen_utc": "2026-10-11 00:55:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1953577": [
        {
            "ioc_value": "164.92.243.20:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:27:58",
            "last_seen_utc": "2026-10-10 10:02:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1953913": [
        {
            "ioc_value": "134.122.91.85:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:27:27",
            "last_seen_utc": "2026-10-10 10:04:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1953933": [
        {
            "ioc_value": "https://xg.396zk.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-06 05:27:25",
            "last_seen_utc": "2026-10-10 00:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "b98dd86b169ec45dd28e99dcad12402a,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954015": [
        {
            "ioc_value": "138.68.101.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-06 05:27:23",
            "last_seen_utc": "2026-10-11 05:47:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954077": [
        {
            "ioc_value": "https://xg.333pwk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-06 05:27:21",
            "last_seen_utc": "2026-10-11 07:32:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e4ff87b25096e0f9d334a8d53cc6b039,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954248": [
        {
            "ioc_value": "186.194.50.58:5930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-06 05:27:15",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5a4378fb90db39f09c7b18d1f314e645,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1954113": [
        {
            "ioc_value": "109.206.247.245:10881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-06 03:45:37",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953658": [
        {
            "ioc_value": "csifrenteatlantica.chp.pt",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-05 22:24:29",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1953451": [
        {
            "ioc_value": "64.227.35.8:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-05 20:05:07",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1953398": [
        {
            "ioc_value": "84.200.91.170:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:45:59",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953397": [
        {
            "ioc_value": "78.17.25.46:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:45:54",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953396": [
        {
            "ioc_value": "77.110.109.204:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:45:53",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953395": [
        {
            "ioc_value": "45.88.91.54:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:45:37",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953394": [
        {
            "ioc_value": "207.189.18.225:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:44:34",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953392": [
        {
            "ioc_value": "207.174.0.227:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953393": [
        {
            "ioc_value": "207.174.0.227:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953391": [
        {
            "ioc_value": "20.160.224.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-05 19:44:30",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953390": [
        {
            "ioc_value": "185.254.96.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:44:10",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953389": [
        {
            "ioc_value": "185.212.129.149:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-05 19:44:08",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953388": [
        {
            "ioc_value": "175.43.223.206:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-05 19:44:00",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953387": [
        {
            "ioc_value": "172.94.99.38:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:43:59",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953386": [
        {
            "ioc_value": "148.163.90.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:43:36",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953385": [
        {
            "ioc_value": "146.19.125.141:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953383": [
        {
            "ioc_value": "143.246.223.165:46048",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953384": [
        {
            "ioc_value": "143.246.223.165:50604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953382": [
        {
            "ioc_value": "13.233.118.170:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-05 19:43:24",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953381": [
        {
            "ioc_value": "102.220.160.198:2500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-05 19:43:05",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953380": [
        {
            "ioc_value": "102.152.29.94:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-05 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1953234": [
        {
            "ioc_value": "1exclusivelandscaping.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-05 18:15:52",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1953207": [
        {
            "ioc_value": "138.68.135.200:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-05 18:01:21",
            "last_seen_utc": "2026-10-10 15:43:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952877": [
        {
            "ioc_value": "206.123.129.234:9985",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-05 14:38:20",
            "last_seen_utc": "2026-10-10 13:18:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,PartnerOne,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952878": [
        {
            "ioc_value": "137.184.108.14:9173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-05 14:38:20",
            "last_seen_utc": "2026-10-09 14:51:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "1c2467af247f67bf0cc44c60ca4d846e,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952882": [
        {
            "ioc_value": "134.122.91.85:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-05 14:38:17",
            "last_seen_utc": "2026-10-11 09:47:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1952883": [
        {
            "ioc_value": "138.68.135.200:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-05 14:38:17",
            "last_seen_utc": "2026-10-11 09:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1952884": [
        {
            "ioc_value": "164.92.243.20:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-05 14:38:17",
            "last_seen_utc": "2026-10-11 09:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/aisuru",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1952800": [
        {
            "ioc_value": "102.117.175.209:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-05 13:05:05",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1952735": [
        {
            "ioc_value": "37.120.206.166:54198",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-05 12:12:28",
            "last_seen_utc": "2026-10-11 03:44:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BK6454198,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952734": [
        {
            "ioc_value": "74.115.172.254:24040",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-05 12:10:37",
            "last_seen_utc": "2026-10-11 09:34:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952684": [
        {
            "ioc_value": "216.9.225.162:9746",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-05 11:29:21",
            "last_seen_utc": "2026-10-11 07:39:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952634": [
        {
            "ioc_value": "https://ax.396zk.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-05 09:54:58",
            "last_seen_utc": "2026-10-11 07:34:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4c6319a44020ed3dbc97141112251a61,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1952591": [
        {
            "ioc_value": "79.238.78.248:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-05 09:45:48",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952589": [
        {
            "ioc_value": "45.32.135.118:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-05 09:45:30",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952590": [
        {
            "ioc_value": "45.32.135.118:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-05 09:45:30",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952588": [
        {
            "ioc_value": "40.223.85.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-05 09:45:19",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952587": [
        {
            "ioc_value": "196.77.100.164:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-05 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952586": [
        {
            "ioc_value": "171.111.194.207:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-05 09:43:55",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952585": [
        {
            "ioc_value": "137.184.139.185:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-05 09:43:29",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952584": [
        {
            "ioc_value": "116.198.18.139:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-05 09:43:20",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952583": [
        {
            "ioc_value": "100.57.14.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-05 09:43:02",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1952482": [
        {
            "ioc_value": "185.236.203.100:62927",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-05 08:13:58",
            "last_seen_utc": "2026-10-09 18:03:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,EMBER 32,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1950368": [
        {
            "ioc_value": "64.227.100.23:2319",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-10-05 06:15:36",
            "last_seen_utc": "2026-10-11 08:34:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "945c9f3c8cddcb7f33efce50a9a949ad,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1951535": [
        {
            "ioc_value": "https://kh.333pwk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-05 06:15:33",
            "last_seen_utc": "2026-10-11 06:51:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "18639d8e3c129270e4d9f4328b3819a1,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1951892": [
        {
            "ioc_value": "102.220.163.203:10213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.cecbot",
            "malware_alias": null,
            "malware_printable": "CECbot",
            "first_seen_utc": "2026-10-05 06:15:29",
            "last_seen_utc": "2026-10-10 23:44:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/cecbot",
            "tags": "android,botnet,cecbot,ddos",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1951638": [
        {
            "ioc_value": "46.246.6.4:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 19:45:23",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951637": [
        {
            "ioc_value": "45.86.60.114:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-04 19:45:20",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951636": [
        {
            "ioc_value": "45.32.135.118:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 19:45:19",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951635": [
        {
            "ioc_value": "217.60.195.85:17845",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-04 19:44:50",
            "last_seen_utc": "2026-10-11 09:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951634": [
        {
            "ioc_value": "207.56.217.24:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-04 19:44:24",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951633": [
        {
            "ioc_value": "186.169.33.116:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-04 19:44:05",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951631": [
        {
            "ioc_value": "185.174.102.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-04 19:43:59",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951632": [
        {
            "ioc_value": "185.174.102.29:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-04 19:43:59",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951630": [
        {
            "ioc_value": "178.16.52.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-04 19:43:56",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951629": [
        {
            "ioc_value": "156.252.163.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951628": [
        {
            "ioc_value": "152.70.24.49:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-04 19:43:35",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951626": [
        {
            "ioc_value": "146.19.125.141:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-04 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951627": [
        {
            "ioc_value": "146.19.125.141:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-04 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951625": [
        {
            "ioc_value": "104.249.10.107:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-04 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1951624": [
        {
            "ioc_value": "102.117.169.140:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-04 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1950365": [
        {
            "ioc_value": "100.61.249.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-04 15:05:05",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1950260": [
        {
            "ioc_value": "slentnaearamisty.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-04 13:14:29",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1950045": [
        {
            "ioc_value": "137.175.102.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-04 10:05:06",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1949993": [
        {
            "ioc_value": "95.182.88.39:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-10-04 09:45:47",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949990": [
        {
            "ioc_value": "93.233.96.34:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:45:44",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949991": [
        {
            "ioc_value": "93.233.96.34:51124",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:45:44",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949992": [
        {
            "ioc_value": "93.233.96.34:51125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:45:44",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949989": [
        {
            "ioc_value": "46.246.84.17:7049",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:45:18",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949988": [
        {
            "ioc_value": "217.60.103.15:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:44:44",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949986": [
        {
            "ioc_value": "217.217.197.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:44:43",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949987": [
        {
            "ioc_value": "217.217.197.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:44:43",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949985": [
        {
            "ioc_value": "2.28.107.84:3322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-04 09:44:18",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949983": [
        {
            "ioc_value": "198.1.241.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:44:16",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949984": [
        {
            "ioc_value": "198.1.241.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:44:16",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949982": [
        {
            "ioc_value": "158.94.208.152:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:43:42",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949978": [
        {
            "ioc_value": "156.252.185.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:43:41",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949979": [
        {
            "ioc_value": "156.252.185.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:43:41",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949980": [
        {
            "ioc_value": "156.252.85.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:43:41",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949981": [
        {
            "ioc_value": "156.252.85.207:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-04 09:43:41",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949977": [
        {
            "ioc_value": "152.70.24.49:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-04 09:43:35",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949974": [
        {
            "ioc_value": "102.55.131.186:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:43:07",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949975": [
        {
            "ioc_value": "102.55.131.186:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:43:07",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949968": [
        {
            "ioc_value": "102.55.131.186:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-04 09:05:04",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1949882": [
        {
            "ioc_value": "106.55.253.229:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-04 08:05:07",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1949876": [
        {
            "ioc_value": "https://al.396zk.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-04 08:00:40",
            "last_seen_utc": "2026-10-11 07:35:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,de4cf22e4d9de058fc3cfd2267ee4cc9,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1949811": [
        {
            "ioc_value": "https://al.333pwk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-04 07:17:55",
            "last_seen_utc": "2026-10-11 07:32:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,de4cf22e4d9de058fc3cfd2267ee4cc9,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1949643": [
        {
            "ioc_value": "217.60.103.131:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-04 06:54:18",
            "last_seen_utc": "2026-10-10 15:44:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1949761": [
        {
            "ioc_value": "45.83.182.68:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-04 06:05:05",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1949760": [
        {
            "ioc_value": "45.142.30.135:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-04 06:05:04",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1949184": [
        {
            "ioc_value": "xo199.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:48",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949144": [
        {
            "ioc_value": "chirca.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949145": [
        {
            "ioc_value": "cloudplusafrica.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949146": [
        {
            "ioc_value": "cnfastener.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949147": [
        {
            "ioc_value": "dermyslabs.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949148": [
        {
            "ioc_value": "drhossambarbary.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949149": [
        {
            "ioc_value": "eufilipedacruz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949150": [
        {
            "ioc_value": "feiratecnomoda.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949151": [
        {
            "ioc_value": "fine-horse.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949152": [
        {
            "ioc_value": "houstonaviationsupplies.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949153": [
        {
            "ioc_value": "ikonicpr.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949154": [
        {
            "ioc_value": "ilpercorso.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949155": [
        {
            "ioc_value": "kambicosmetics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949156": [
        {
            "ioc_value": "lom-informatique.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949158": [
        {
            "ioc_value": "metroxusa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949159": [
        {
            "ioc_value": "monetybielsko.pl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949161": [
        {
            "ioc_value": "oslermedicalcentre.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949162": [
        {
            "ioc_value": "ourfamilydecides.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949163": [
        {
            "ioc_value": "seatacairporttransportation.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949164": [
        {
            "ioc_value": "signhubuae.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949165": [
        {
            "ioc_value": "siweiriji.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949166": [
        {
            "ioc_value": "systemanova.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949167": [
        {
            "ioc_value": "taykhasurgical.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949168": [
        {
            "ioc_value": "vivianahernandezart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949169": [
        {
            "ioc_value": "wearstreamtext.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:47",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949140": [
        {
            "ioc_value": "advsalles.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:46",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949141": [
        {
            "ioc_value": "amazoniarentacar.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:46",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949142": [
        {
            "ioc_value": "amisosmimarlik.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:46",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949143": [
        {
            "ioc_value": "blackscreamfest.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 21:04:46",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1949016": [
        {
            "ioc_value": "5.175.169.209:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 19:45:07",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949015": [
        {
            "ioc_value": "46.246.84.17:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 19:45:05",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949013": [
        {
            "ioc_value": "207.56.217.22:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949014": [
        {
            "ioc_value": "207.56.217.24:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949012": [
        {
            "ioc_value": "2.26.30.186:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 19:44:10",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949011": [
        {
            "ioc_value": "169.58.249.24:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-03 19:43:44",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949010": [
        {
            "ioc_value": "167.99.101.176:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 19:43:43",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949009": [
        {
            "ioc_value": "165.232.52.148:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949008": [
        {
            "ioc_value": "154.18.239.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949007": [
        {
            "ioc_value": "153.52.177.187:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949006": [
        {
            "ioc_value": "147.45.61.46:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 19:43:29",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949005": [
        {
            "ioc_value": "128.90.167.136:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 19:43:18",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949004": [
        {
            "ioc_value": "104.248.212.139:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 19:43:10",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949003": [
        {
            "ioc_value": "102.55.131.186:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 19:43:06",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1949002": [
        {
            "ioc_value": "102.117.160.70:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 19:43:02",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948988": [
        {
            "ioc_value": "checkdvvc99.cc",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-03 19:07:07",
            "last_seen_utc": "2026-10-09 14:16:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1948987": [
        {
            "ioc_value": "179.43.170.151:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-03 19:05:04",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1948932": [
        {
            "ioc_value": "ia-me.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 18:44:30",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://www.clickfixed.uk/intel/18451",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "ClickFixer"
        }
    ],
    "1948779": [
        {
            "ioc_value": "87.120.107.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 15:05:04",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1948674": [
        {
            "ioc_value": "144.172.68.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-03 13:45:51",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948673": [
        {
            "ioc_value": "agent.cloudfiledisk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-03 13:45:39",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948506": [
        {
            "ioc_value": "vale-quaeum-a4hc9.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-03 11:30:04",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1948399": [
        {
            "ioc_value": "94.26.83.60:2398",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-03 09:45:40",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948397": [
        {
            "ioc_value": "62.210.87.233:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-03 09:45:20",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948396": [
        {
            "ioc_value": "45.153.34.250:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 09:45:06",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948395": [
        {
            "ioc_value": "45.139.104.180:55005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 09:45:03",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948393": [
        {
            "ioc_value": "31.56.209.82:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 09:44:51",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948394": [
        {
            "ioc_value": "31.56.209.82:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 09:44:51",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948391": [
        {
            "ioc_value": "217.60.102.47:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948392": [
        {
            "ioc_value": "217.60.102.47:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948389": [
        {
            "ioc_value": "189.141.46.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-03 09:44:04",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948390": [
        {
            "ioc_value": "190.255.80.136:8092",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-03 09:44:04",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948388": [
        {
            "ioc_value": "185.241.211.16:2021",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 09:43:58",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948386": [
        {
            "ioc_value": "164.90.190.203:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-03 09:43:45",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948385": [
        {
            "ioc_value": "145.63.136.150:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948384": [
        {
            "ioc_value": "104.250.167.93:2704",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-03 09:43:11",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1948383": [
        {
            "ioc_value": "104.239.66.182:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-03 09:43:10",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1947919": [
        {
            "ioc_value": "yuanma-hui.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:56",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947741": [
        {
            "ioc_value": "wildhareevents.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:13",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947742": [
        {
            "ioc_value": "wordpresshjalp.se",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:13",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947743": [
        {
            "ioc_value": "wpsoffok.com.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:13",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947719": [
        {
            "ioc_value": "torresirrigationservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947721": [
        {
            "ioc_value": "transcargoconnect.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947722": [
        {
            "ioc_value": "treesofbuddha.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947723": [
        {
            "ioc_value": "trianguloglobal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947724": [
        {
            "ioc_value": "truewayfitness.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947735": [
        {
            "ioc_value": "viewersparkhotel.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947736": [
        {
            "ioc_value": "villasnet.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947737": [
        {
            "ioc_value": "villasyates.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947739": [
        {
            "ioc_value": "vvhindia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:12",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947697": [
        {
            "ioc_value": "stockholmriskettan.se",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947698": [
        {
            "ioc_value": "strongenerjiltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947701": [
        {
            "ioc_value": "susinail.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947702": [
        {
            "ioc_value": "syantigroup.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947703": [
        {
            "ioc_value": "tabernamacaenvenenada.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947704": [
        {
            "ioc_value": "tacografosblumenau.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947705": [
        {
            "ioc_value": "tallerenteatinos.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947706": [
        {
            "ioc_value": "targetdigitalmarketing.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947707": [
        {
            "ioc_value": "techjunctionltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947711": [
        {
            "ioc_value": "terraconsult.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947712": [
        {
            "ioc_value": "terrapoetica.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947713": [
        {
            "ioc_value": "theblueprintbox.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947716": [
        {
            "ioc_value": "themadisonrange.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947717": [
        {
            "ioc_value": "therovegroup.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:11",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947680": [
        {
            "ioc_value": "sanatansewasansthan.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947686": [
        {
            "ioc_value": "sevinjoojeh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947688": [
        {
            "ioc_value": "shivanienterprise.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947690": [
        {
            "ioc_value": "sipsandsightstravel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947691": [
        {
            "ioc_value": "siscomputer.gr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947692": [
        {
            "ioc_value": "smkn4kepahiang.sch.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947696": [
        {
            "ioc_value": "stalwartintegratedschool.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:10",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947667": [
        {
            "ioc_value": "quantumbiogenix.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947669": [
        {
            "ioc_value": "rclabor.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947670": [
        {
            "ioc_value": "rcmsocal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947673": [
        {
            "ioc_value": "retc.luiss.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947674": [
        {
            "ioc_value": "rishipokhrel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947676": [
        {
            "ioc_value": "royalshadi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947677": [
        {
            "ioc_value": "rxexpressshop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947679": [
        {
            "ioc_value": "s3eng.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:09",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947661": [
        {
            "ioc_value": "piramilakitchens.ca",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:08",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947662": [
        {
            "ioc_value": "pneumaxes.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:21:08",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947640": [
        {
            "ioc_value": "muhiku.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947646": [
        {
            "ioc_value": "nepochopis.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947647": [
        {
            "ioc_value": "nerenco.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947648": [
        {
            "ioc_value": "niknew.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947650": [
        {
            "ioc_value": "okoldtimer.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947654": [
        {
            "ioc_value": "ozkiricigidasaniyaveticaret.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947658": [
        {
            "ioc_value": "passportmakers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:24",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947625": [
        {
            "ioc_value": "localbusinesscourses.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:23",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947627": [
        {
            "ioc_value": "lojadetemplates.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:23",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947628": [
        {
            "ioc_value": "lucaburgio.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:23",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947631": [
        {
            "ioc_value": "maxfel.se",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:23",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947634": [
        {
            "ioc_value": "metuong.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:23",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947609": [
        {
            "ioc_value": "jamexgroup.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947611": [
        {
            "ioc_value": "kapimeble.pl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947613": [
        {
            "ioc_value": "khobephiendai.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947614": [
        {
            "ioc_value": "kindercan.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947615": [
        {
            "ioc_value": "kindercan.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947617": [
        {
            "ioc_value": "klubk9.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947620": [
        {
            "ioc_value": "leondanceart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947621": [
        {
            "ioc_value": "lessetcabretes.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947623": [
        {
            "ioc_value": "lightdsc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:22",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947588": [
        {
            "ioc_value": "handyhomepets.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947589": [
        {
            "ioc_value": "hastidecodesign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947590": [
        {
            "ioc_value": "hdairporttransfers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947591": [
        {
            "ioc_value": "hedeke.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947593": [
        {
            "ioc_value": "homu.ec",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947594": [
        {
            "ioc_value": "hopla.cz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947595": [
        {
            "ioc_value": "hostpci.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947596": [
        {
            "ioc_value": "hymsolucionesmetalicas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947598": [
        {
            "ioc_value": "imagencap.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947599": [
        {
            "ioc_value": "impulse.com.my",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947600": [
        {
            "ioc_value": "industrialvisionstudio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947603": [
        {
            "ioc_value": "intuitivemassage.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947604": [
        {
            "ioc_value": "irankarkonan.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:21",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947573": [
        {
            "ioc_value": "freddysfoodmarket.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947575": [
        {
            "ioc_value": "ganadorainternational.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947576": [
        {
            "ioc_value": "gcdplagas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947578": [
        {
            "ioc_value": "glitteronlights.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947581": [
        {
            "ioc_value": "goldsmithsglobal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947584": [
        {
            "ioc_value": "growthyatra.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947585": [
        {
            "ioc_value": "grupovisbal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:20:20",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947567": [
        {
            "ioc_value": "fakemoneys.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:02",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947569": [
        {
            "ioc_value": "finnboxsiivous.fi",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:02",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947570": [
        {
            "ioc_value": "firewoodsupplyco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:02",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947549": [
        {
            "ioc_value": "draugustovillafisioterapia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947550": [
        {
            "ioc_value": "dynamiccommsource.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947551": [
        {
            "ioc_value": "eastiowamech.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947552": [
        {
            "ioc_value": "eatmybowls.dk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947553": [
        {
            "ioc_value": "eboy.gr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947554": [
        {
            "ioc_value": "edranovan.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947555": [
        {
            "ioc_value": "elementsbyrobertsantana.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947558": [
        {
            "ioc_value": "elvenezolano.tv",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947560": [
        {
            "ioc_value": "enginexgymsupply.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947563": [
        {
            "ioc_value": "escoladeconfeitariadocedesejofe.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947565": [
        {
            "ioc_value": "fabriciofameli.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947566": [
        {
            "ioc_value": "facevaucluse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:01",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947527": [
        {
            "ioc_value": "chizzyexpressfreight.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947529": [
        {
            "ioc_value": "clinicaafirmativa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947530": [
        {
            "ioc_value": "cocochicken.pl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947532": [
        {
            "ioc_value": "construtorariomax.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947535": [
        {
            "ioc_value": "crossfitlandes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947537": [
        {
            "ioc_value": "cyberix.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947543": [
        {
            "ioc_value": "deltafencetexas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947546": [
        {
            "ioc_value": "deputydepartment.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:19:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947505": [
        {
            "ioc_value": "blackcode.my",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947506": [
        {
            "ioc_value": "bomdemarketing.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947508": [
        {
            "ioc_value": "bottegadesires.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947509": [
        {
            "ioc_value": "boxart21.rs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947510": [
        {
            "ioc_value": "brilliantulifecoach.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947511": [
        {
            "ioc_value": "brumtengenharia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947513": [
        {
            "ioc_value": "business.punkthotel.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947514": [
        {
            "ioc_value": "buyoldshop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947516": [
        {
            "ioc_value": "camilamaffini.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947518": [
        {
            "ioc_value": "capricorneducation.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947519": [
        {
            "ioc_value": "cardsmmj.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947522": [
        {
            "ioc_value": "carparts.com.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947523": [
        {
            "ioc_value": "celebratestill.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947481": [
        {
            "ioc_value": "alahdcoal.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947482": [
        {
            "ioc_value": "alchemyweightloss.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947487": [
        {
            "ioc_value": "android.trinea.cn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947488": [
        {
            "ioc_value": "angelagricarebd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947489": [
        {
            "ioc_value": "annemariejohnson.ca",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947490": [
        {
            "ioc_value": "arrayedlifestyle.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947491": [
        {
            "ioc_value": "articlesdream.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947492": [
        {
            "ioc_value": "asparpharmaceuticals.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947493": [
        {
            "ioc_value": "assistanceaudit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947494": [
        {
            "ioc_value": "astermill.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947496": [
        {
            "ioc_value": "axeandarcade.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947498": [
        {
            "ioc_value": "barakahbullies.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947499": [
        {
            "ioc_value": "beatify.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947501": [
        {
            "ioc_value": "betkam.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:58",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947470": [
        {
            "ioc_value": "13llogin.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947472": [
        {
            "ioc_value": "321eventhub.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947475": [
        {
            "ioc_value": "abnet.ca",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947476": [
        {
            "ioc_value": "actandthrive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1947479": [
        {
            "ioc_value": "airesdelvalle.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-03 07:18:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1946053": [
        {
            "ioc_value": "https://rz.333pwk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-03 06:04:05",
            "last_seen_utc": "2026-10-11 07:35:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "65e82f936ed593b809cc507d7ad114e5,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1946109": [
        {
            "ioc_value": "https://rz.396zk.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-03 06:04:05",
            "last_seen_utc": "2026-10-10 23:14:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "65e82f936ed593b809cc507d7ad114e5,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1946187": [
        {
            "ioc_value": "94.26.68.68:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-03 06:04:01",
            "last_seen_utc": "2026-10-11 05:17:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,services",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1946243": [
        {
            "ioc_value": "https://104.105.28.52",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-03 06:03:56",
            "last_seen_utc": "2026-10-11 09:48:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a2986ad16988a9513a3d08d0c842ae18,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1946188": [
        {
            "ioc_value": "odamizinegolden.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 01:14:06",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946189": [
        {
            "ioc_value": "thaiunitedawapaperltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 01:14:06",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946186": [
        {
            "ioc_value": "23.132.164.72:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-03 01:05:05",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946136": [
        {
            "ioc_value": "jakichudorkar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:23:18",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946132": [
        {
            "ioc_value": "heatfixpro.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:23:17",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946133": [
        {
            "ioc_value": "japanauto-trading.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:23:17",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946134": [
        {
            "ioc_value": "kuasampara.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:23:17",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946120": [
        {
            "ioc_value": "mabeling.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:13:15",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946113": [
        {
            "ioc_value": "loveherwildpodcast.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:02:44",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946114": [
        {
            "ioc_value": "gmems.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:02:44",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946112": [
        {
            "ioc_value": "mirigrace.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-03 00:02:43",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946058": [
        {
            "ioc_value": "anakissilapersonalizados.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-02 23:17:39",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946060": [
        {
            "ioc_value": "archcleaning.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-02 23:17:39",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1946056": [
        {
            "ioc_value": "51.79.220.125:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 23:05:04",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1945530": [
        {
            "ioc_value": "https://ti.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-02 20:44:42",
            "last_seen_utc": "2026-10-10 23:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1945535": [
        {
            "ioc_value": "https://ti.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-02 20:44:41",
            "last_seen_utc": "2026-10-11 07:34:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2f18de214042c96f5cddd8c9b9563da6,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1945782": [
        {
            "ioc_value": "91.92.41.66:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:45:55",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945783": [
        {
            "ioc_value": "91.92.41.92:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:45:55",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945781": [
        {
            "ioc_value": "46.246.84.19:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:45:30",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945780": [
        {
            "ioc_value": "40.160.135.244:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-10-02 19:45:16",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945779": [
        {
            "ioc_value": "31.56.209.82:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:45:05",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945778": [
        {
            "ioc_value": "23.132.164.72:20",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:44:58",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945777": [
        {
            "ioc_value": "217.60.102.47:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:44:53",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945776": [
        {
            "ioc_value": "216.250.252.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:44:52",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945775": [
        {
            "ioc_value": "2.59.132.206:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:44:25",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945774": [
        {
            "ioc_value": "2.27.13.90:8686",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:44:24",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945773": [
        {
            "ioc_value": "160.179.238.25:5001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945772": [
        {
            "ioc_value": "160.179.238.25:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945771": [
        {
            "ioc_value": "150.241.226.20:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:43:37",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945770": [
        {
            "ioc_value": "13.143.247.153:2021",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 19:43:23",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945769": [
        {
            "ioc_value": "109.199.114.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 19:43:17",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945767": [
        {
            "ioc_value": "104.239.66.182:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:43:11",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945768": [
        {
            "ioc_value": "104.239.66.182:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 19:43:11",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945611": [
        {
            "ioc_value": "23.132.164.72:1080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 18:05:04",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1945552": [
        {
            "ioc_value": "indian4club.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-02 17:37:24",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1945540": [
        {
            "ioc_value": "fitwellscaffolding.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-02 17:06:40",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1945539": [
        {
            "ioc_value": "102.117.170.218:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 17:05:07",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1945494": [
        {
            "ioc_value": "atelier-merci.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-10-02 15:07:22",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1945349": [
        {
            "ioc_value": "159.75.202.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-02 13:46:27",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945348": [
        {
            "ioc_value": "141.255.166.178:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-02 13:46:24",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945346": [
        {
            "ioc_value": "coral-thistle-kilmkruon.top",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-02 13:36:29",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1945339": [
        {
            "ioc_value": "68.178.205.17:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-02 13:13:03",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/68.178.205.17#443",
            "tags": "Havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1945280": [
        {
            "ioc_value": "92.51.46.35:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-02 09:45:49",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945279": [
        {
            "ioc_value": "78.17.25.46:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 09:45:37",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945278": [
        {
            "ioc_value": "64.177.45.143:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-02 09:45:31",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945277": [
        {
            "ioc_value": "45.93.95.212:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 09:45:22",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945275": [
        {
            "ioc_value": "45.135.119.121:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 09:45:13",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945276": [
        {
            "ioc_value": "45.139.104.199:55006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 09:45:13",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945274": [
        {
            "ioc_value": "31.56.19.40:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-02 09:44:55",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945273": [
        {
            "ioc_value": "217.60.184.45:8855",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-02 09:44:46",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945272": [
        {
            "ioc_value": "216.203.20.87:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-02 09:44:45",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945269": [
        {
            "ioc_value": "207.57.162.48:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-02 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945270": [
        {
            "ioc_value": "207.57.163.104:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-02 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945271": [
        {
            "ioc_value": "207.57.163.104:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-02 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945268": [
        {
            "ioc_value": "203.161.47.31:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-02 09:44:22",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945267": [
        {
            "ioc_value": "193.24.123.206:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-02 09:44:12",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945266": [
        {
            "ioc_value": "180.76.97.85:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-02 09:43:56",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945265": [
        {
            "ioc_value": "158.94.210.16:2853",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-02 09:43:42",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945264": [
        {
            "ioc_value": "149.88.76.74:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-02 09:43:33",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945263": [
        {
            "ioc_value": "149.202.227.107:7444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 09:43:32",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945262": [
        {
            "ioc_value": "143.202.93.210:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-02 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945261": [
        {
            "ioc_value": "120.79.146.35:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-02 09:43:18",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1945253": [
        {
            "ioc_value": "http://43.246.210.160:443/?h=43.246.210.160&p=443&t=tcp&a=w32&stage=true",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-10-02 09:42:43",
            "last_seen_utc": "2026-10-10 21:12:30",
            "confidence_level": 85,
            "is_compromised": true,
            "reference": null,
            "tags": "exe,loader",
            "anonymous": 0,
            "reporter": "whack_sh"
        }
    ],
    "1945218": [
        {
            "ioc_value": "https://zu.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-02 08:27:46",
            "last_seen_utc": "2026-10-11 07:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1944969": [
        {
            "ioc_value": "https://zu.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-02 06:31:04",
            "last_seen_utc": "2026-10-10 20:39:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1944249": [
        {
            "ioc_value": "https://st.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-02 06:30:52",
            "last_seen_utc": "2026-10-11 05:17:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1944246": [
        {
            "ioc_value": "https://st.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-02 06:30:51",
            "last_seen_utc": "2026-10-11 07:45:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4c6319a44020ed3dbc97141112251a61,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1944958": [
        {
            "ioc_value": "68.178.202.150:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-02 04:47:57",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/68.178.202.150#443",
            "tags": "Havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1944957": [
        {
            "ioc_value": "192.169.176.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-02 04:47:54",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/192.169.176.54#443",
            "tags": "Havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1944797": [
        {
            "ioc_value": "amber-weave-otter-luor.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 23:21:26",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944639": [
        {
            "ioc_value": "shepherdsbushmobiletyrefitting.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 22:04:03",
            "last_seen_utc": "2026-10-09 23:13:29",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,LOM",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944190": [
        {
            "ioc_value": "94.249.207.133:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-01 19:45:49",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944189": [
        {
            "ioc_value": "91.92.41.92:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:45:45",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944188": [
        {
            "ioc_value": "45.139.104.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:45:11",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944187": [
        {
            "ioc_value": "45.139.104.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:45:10",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944186": [
        {
            "ioc_value": "35.212.135.58:6688",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-01 19:45:01",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944185": [
        {
            "ioc_value": "34.22.149.111:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-01 19:45:00",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944184": [
        {
            "ioc_value": "23.94.212.126:8911",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-01 19:44:54",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944183": [
        {
            "ioc_value": "23.132.164.73:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 19:44:52",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944182": [
        {
            "ioc_value": "207.57.162.48:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-10-01 19:44:25",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944180": [
        {
            "ioc_value": "170.78.199.162:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-10-01 19:43:50",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944179": [
        {
            "ioc_value": "160.250.181.159:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:43:45",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944178": [
        {
            "ioc_value": "160.119.76.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:43:44",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944177": [
        {
            "ioc_value": "153.80.249.4:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:43:36",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944175": [
        {
            "ioc_value": "150.241.226.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944176": [
        {
            "ioc_value": "150.241.226.20:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944173": [
        {
            "ioc_value": "117.55.235.249:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-01 19:43:17",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944172": [
        {
            "ioc_value": "107.174.212.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 19:43:14",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944171": [
        {
            "ioc_value": "107.172.133.178:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 19:43:13",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1944106": [
        {
            "ioc_value": "rumahbersalinmedicalhacking.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:44",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944107": [
        {
            "ioc_value": "techplnt.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:44",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944109": [
        {
            "ioc_value": "thecretannutritionist.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:44",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944110": [
        {
            "ioc_value": "visaliatile.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:44",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944095": [
        {
            "ioc_value": "jeffcotogether.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944096": [
        {
            "ioc_value": "lald.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944098": [
        {
            "ioc_value": "locaspace.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944099": [
        {
            "ioc_value": "mahomahtab-dessert.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944100": [
        {
            "ioc_value": "mior.co.il",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944102": [
        {
            "ioc_value": "nationalhilift.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944103": [
        {
            "ioc_value": "olympiahospital.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944104": [
        {
            "ioc_value": "primebalance.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944084": [
        {
            "ioc_value": "asesorialegal.cr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944085": [
        {
            "ioc_value": "csua-asbl.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944086": [
        {
            "ioc_value": "direktinvest-photovoltaik.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944087": [
        {
            "ioc_value": "elboinn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944088": [
        {
            "ioc_value": "energumsolutions.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944089": [
        {
            "ioc_value": "energybalanceyoga.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944090": [
        {
            "ioc_value": "everglorylines.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944091": [
        {
            "ioc_value": "hanifapapers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944092": [
        {
            "ioc_value": "harekrishnalod.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944094": [
        {
            "ioc_value": "hrcsnews.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:42",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1944083": [
        {
            "ioc_value": "anchorpointmarine.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-10-01 18:43:41",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1943873": [
        {
            "ioc_value": "43.139.239.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-01 13:46:22",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943852": [
        {
            "ioc_value": "13.61.179.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-10-01 13:05:09",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1943710": [
        {
            "ioc_value": "https://zi.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 11:03:49",
            "last_seen_utc": "2026-10-11 03:06:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4c6319a44020ed3dbc97141112251a61,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943779": [
        {
            "ioc_value": "https://zi.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 11:03:46",
            "last_seen_utc": "2026-10-11 07:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2f18de214042c96f5cddd8c9b9563da6,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943746": [
        {
            "ioc_value": "93.185.165.104:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-01 10:05:05",
            "last_seen_utc": "2026-10-11 08:17:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1943744": [
        {
            "ioc_value": "85.120.255.76:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-01 09:45:35",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943743": [
        {
            "ioc_value": "67.205.131.19:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-01 09:45:26",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943742": [
        {
            "ioc_value": "45.139.104.232:55009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 09:45:07",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943741": [
        {
            "ioc_value": "41.43.184.224:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:45:03",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943740": [
        {
            "ioc_value": "23.94.252.242:2052",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-10-01 09:44:50",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943738": [
        {
            "ioc_value": "23.132.164.73:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:44:48",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943739": [
        {
            "ioc_value": "23.132.164.73:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:44:48",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943737": [
        {
            "ioc_value": "201.79.51.29:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-01 09:44:20",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943736": [
        {
            "ioc_value": "185.241.211.167:8050",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:44:00",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943735": [
        {
            "ioc_value": "160.119.76.118:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:43:43",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943733": [
        {
            "ioc_value": "144.31.251.6:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-10-01 09:43:30",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943731": [
        {
            "ioc_value": "143.198.176.61:33335",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-10-01 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943729": [
        {
            "ioc_value": "139.64.172.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-10-01 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943726": [
        {
            "ioc_value": "137.184.139.185:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-10-01 09:43:26",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943723": [
        {
            "ioc_value": "130.61.61.21:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-10-01 09:43:23",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943714": [
        {
            "ioc_value": "105.137.170.202:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:43:13",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943715": [
        {
            "ioc_value": "105.137.170.202:5001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-10-01 09:43:13",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943713": [
        {
            "ioc_value": "103.228.171.113:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-10-01 09:43:08",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943700": [
        {
            "ioc_value": "143.244.155.53:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-01 09:11:09",
            "last_seen_utc": "2026-10-11 00:09:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/blob/main/aisuru/README.md",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943703": [
        {
            "ioc_value": "104.248.155.168:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-01 09:11:07",
            "last_seen_utc": "2026-10-10 18:03:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/blob/main/aisuru/README.md",
            "tags": "airashi,aisuru,botnet,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943618": [
        {
            "ioc_value": "https://af.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 08:14:22",
            "last_seen_utc": "2026-10-11 07:44:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943648": [
        {
            "ioc_value": "165.245.250.162:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-01 08:14:21",
            "last_seen_utc": "2026-10-11 06:08:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943672": [
        {
            "ioc_value": "217.64.148.147:64562",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-01 08:14:20",
            "last_seen_utc": "2026-10-11 06:03:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,WINWIN",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943641": [
        {
            "ioc_value": "154.12.117.217:2408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-10-01 06:55:23",
            "last_seen_utc": "2026-10-11 08:04:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e7de6197ad8312d8722b477d3ca988e196f17be5f5498eedc4b8d3c6c3791993/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943602": [
        {
            "ioc_value": "134.122.68.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:38",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943603": [
        {
            "ioc_value": "137.184.100.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:37",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943604": [
        {
            "ioc_value": "138.68.128.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:37",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943605": [
        {
            "ioc_value": "157.230.254.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:36",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943606": [
        {
            "ioc_value": "157.245.188.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:36",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943607": [
        {
            "ioc_value": "167.172.93.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:34",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943608": [
        {
            "ioc_value": "168.144.113.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:34",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943610": [
        {
            "ioc_value": "206.189.2.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:32",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943611": [
        {
            "ioc_value": "209.38.240.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-10-01 06:00:31",
            "last_seen_utc": "2026-10-11 06:37:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1943239": [
        {
            "ioc_value": "https://lo.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 05:17:55",
            "last_seen_utc": "2026-10-11 03:20:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943366": [
        {
            "ioc_value": "https://lo.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 05:17:44",
            "last_seen_utc": "2026-10-11 07:35:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e3cbc03b68edf5a9406e35280bab2438,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943375": [
        {
            "ioc_value": "142.93.6.168:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-10-01 05:17:35",
            "last_seen_utc": "2026-10-11 06:11:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943438": [
        {
            "ioc_value": "https://up.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 05:17:28",
            "last_seen_utc": "2026-10-11 01:09:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4c6319a44020ed3dbc97141112251a61,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943507": [
        {
            "ioc_value": "https://up.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-10-01 05:17:23",
            "last_seen_utc": "2026-10-11 07:34:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4c6319a44020ed3dbc97141112251a61,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943506": [
        {
            "ioc_value": "156.254.20.48:5998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-10-01 03:46:17",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943459": [
        {
            "ioc_value": "130.94.67.107:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-01 02:05:04",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1943409": [
        {
            "ioc_value": "tantrikashaman.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-01 00:27:10",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1943408": [
        {
            "ioc_value": "camilagazola.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-10-01 00:27:09",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1943251": [
        {
            "ioc_value": "93.185.167.211:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-30 19:46:25",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943250": [
        {
            "ioc_value": "77.241.196.163:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-30 19:46:08",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943248": [
        {
            "ioc_value": "51.20.9.206:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-09-30 19:45:57",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943249": [
        {
            "ioc_value": "52.196.90.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-09-30 19:45:57",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943247": [
        {
            "ioc_value": "45.225.135.166:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:45:48",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943244": [
        {
            "ioc_value": "45.146.91.83:1908",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-30 19:45:42",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943243": [
        {
            "ioc_value": "36.94.34.18:31845",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-09-30 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943242": [
        {
            "ioc_value": "31.6.11.79:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 19:45:27",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943241": [
        {
            "ioc_value": "202.146.222.156:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943240": [
        {
            "ioc_value": "202.146.222.156:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:44:41",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943237": [
        {
            "ioc_value": "192.253.229.23:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:44:28",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943238": [
        {
            "ioc_value": "192.253.229.23:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:44:28",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943236": [
        {
            "ioc_value": "192.142.10.165:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 19:44:24",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943235": [
        {
            "ioc_value": "130.61.61.21:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-09-30 19:43:30",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943232": [
        {
            "ioc_value": "103.114.216.59:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943233": [
        {
            "ioc_value": "103.114.216.59:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943234": [
        {
            "ioc_value": "103.114.216.59:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1943080": [
        {
            "ioc_value": "142.93.6.168:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 19:00:35",
            "last_seen_utc": "2026-10-11 06:07:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943175": [
        {
            "ioc_value": "190.144.146.90:5510",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 19:00:27",
            "last_seen_utc": "2026-10-09 22:28:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AGOSTO 05 MUCHACHA 2026,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942970": [
        {
            "ioc_value": "23.189.104.198:2445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 17:06:42",
            "last_seen_utc": "2026-10-09 10:58:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Yok",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942982": [
        {
            "ioc_value": "104.248.155.168:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 17:06:40",
            "last_seen_utc": "2026-10-11 04:57:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943028": [
        {
            "ioc_value": "https://x2.369jk.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-30 17:06:38",
            "last_seen_utc": "2026-10-11 03:30:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "43c9f02b8b98cfc9c3e446da473793a2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1943021": [
        {
            "ioc_value": "147.50.252.47:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 16:49:47",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1943023": [
        {
            "ioc_value": "147.50.252.47:9977",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 16:49:47",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1942964": [
        {
            "ioc_value": "155.103.69.174:4981",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 15:45:30",
            "last_seen_utc": "2026-10-11 06:03:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9f0df64cc8a15b2c96e639a975acb9f54ff26721dc60a8035d4bbc65476485e7/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942921": [
        {
            "ioc_value": "https://x2.332toto.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-30 14:49:40",
            "last_seen_utc": "2026-10-11 07:36:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "06b5cfefd856c63c42a482c60c61bed0,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942922": [
        {
            "ioc_value": "159.223.24.190:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 14:49:40",
            "last_seen_utc": "2026-10-10 11:46:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942927": [
        {
            "ioc_value": "91.92.41.39:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 14:49:39",
            "last_seen_utc": "2026-10-11 06:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Remote",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942898": [
        {
            "ioc_value": "217.64.148.139:56151",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 13:01:04",
            "last_seen_utc": "2026-10-11 03:59:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/47628bf5d571084ccd174e03c02efb2e2211b69d88a12445829344b1cdeea945/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942797": [
        {
            "ioc_value": "143.244.155.53:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:57:03",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942807": [
        {
            "ioc_value": "65.20.107.184:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 09:45:42",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942806": [
        {
            "ioc_value": "62.113.106.171:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-30 09:45:39",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942802": [
        {
            "ioc_value": "45.88.91.165:3535",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-30 09:45:29",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942799": [
        {
            "ioc_value": "37.72.168.199:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 09:45:10",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942798": [
        {
            "ioc_value": "198.211.102.128:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-30 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942796": [
        {
            "ioc_value": "172.81.182.244:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 09:43:55",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942795": [
        {
            "ioc_value": "162.243.6.201:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-30 09:43:50",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942794": [
        {
            "ioc_value": "159.223.145.166:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-09-30 09:43:48",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942791": [
        {
            "ioc_value": "156.252.92.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-30 09:43:46",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942792": [
        {
            "ioc_value": "157.20.182.14:9997",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 09:43:46",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942793": [
        {
            "ioc_value": "157.20.182.15:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 09:43:46",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942790": [
        {
            "ioc_value": "13.143.247.153:2010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-30 09:43:24",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942789": [
        {
            "ioc_value": "128.90.135.200:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-30 09:43:21",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942788": [
        {
            "ioc_value": "116.213.43.169:29443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-30 09:43:17",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942787": [
        {
            "ioc_value": "103.114.216.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-30 09:43:07",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942766": [
        {
            "ioc_value": "http://bescaphoto.ga/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-09-30 09:28:46",
            "last_seen_utc": "2026-10-11 09:34:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942769": [
        {
            "ioc_value": "165.245.250.162:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:28:46",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942770": [
        {
            "ioc_value": "104.248.155.168:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:28:45",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942771": [
        {
            "ioc_value": "142.93.6.168:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:28:45",
            "last_seen_utc": "2026-10-11 09:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942772": [
        {
            "ioc_value": "167.172.71.210:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:28:45",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942773": [
        {
            "ioc_value": "159.223.24.190:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:28:44",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942774": [
        {
            "ioc_value": "143.244.155.53:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-09-30 09:28:44",
            "last_seen_utc": "2026-10-11 04:27:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942761": [
        {
            "ioc_value": "155.103.70.232:14444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 08:15:53",
            "last_seen_utc": "2026-10-11 05:06:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942412": [
        {
            "ioc_value": "158.94.209.12:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-30 06:02:27",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "GAYINT_DOT_ORG"
        }
    ],
    "1942050": [
        {
            "ioc_value": "https://bw.32naga.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-30 05:49:50",
            "last_seen_utc": "2026-10-11 07:37:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2f18de214042c96f5cddd8c9b9563da6,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942167": [
        {
            "ioc_value": "http://144.31.151.8/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-09-30 05:49:38",
            "last_seen_utc": "2026-10-11 09:14:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6k,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942168": [
        {
            "ioc_value": "159.89.166.50:8531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-09-30 05:49:36",
            "last_seen_utc": "2026-10-11 09:49:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5a4378fb90db39f09c7b18d1f314e645,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942312": [
        {
            "ioc_value": "130.94.107.174:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-30 05:49:06",
            "last_seen_utc": "2026-10-11 02:26:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1942313": [
        {
            "ioc_value": "130.94.17.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-30 05:49:05",
            "last_seen_utc": "2026-10-11 02:26:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1942314": [
        {
            "ioc_value": "38.60.238.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-30 05:49:04",
            "last_seen_utc": "2026-10-11 02:26:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1942554": [
        {
            "ioc_value": "155.103.69.249:2535",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-30 05:48:53",
            "last_seen_utc": "2026-10-11 00:30:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1942585": [
        {
            "ioc_value": "8.166.128.186:50053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-30 03:46:41",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942076": [
        {
            "ioc_value": "80.76.49.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:45:49",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942070": [
        {
            "ioc_value": "46.151.182.21:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942071": [
        {
            "ioc_value": "46.151.182.21:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942073": [
        {
            "ioc_value": "46.151.182.21:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:45:31",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942066": [
        {
            "ioc_value": "45.146.90.209:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:45:24",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942067": [
        {
            "ioc_value": "45.146.90.210:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-29 19:45:24",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942065": [
        {
            "ioc_value": "31.6.11.231:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-29 19:45:10",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942063": [
        {
            "ioc_value": "31.56.209.140:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:45:07",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942064": [
        {
            "ioc_value": "31.56.209.140:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-29 19:45:07",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942061": [
        {
            "ioc_value": "185.254.96.135:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:44:08",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942062": [
        {
            "ioc_value": "185.254.99.169:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:44:08",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942059": [
        {
            "ioc_value": "172.93.161.96:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:43:56",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942060": [
        {
            "ioc_value": "172.93.161.96:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:43:56",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942058": [
        {
            "ioc_value": "172.111.139.78:9991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-29 19:43:53",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942057": [
        {
            "ioc_value": "144.31.6.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942056": [
        {
            "ioc_value": "144.126.155.182:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-29 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1942051": [
        {
            "ioc_value": "104.219.238.196:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-29 19:05:04",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1941742": [
        {
            "ioc_value": "43.225.157.17:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-29 12:43:46",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/43.225.157.17#4321",
            "tags": "adaptix,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1941741": [
        {
            "ioc_value": "165.22.104.177:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-29 12:43:45",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/165.22.104.177#4321",
            "tags": "adaptix,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1941740": [
        {
            "ioc_value": "20.193.139.57:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 12:43:10",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/20.193.139.57#7443",
            "tags": "mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1941664": [
        {
            "ioc_value": "https://ed.32naga.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-29 12:10:35",
            "last_seen_utc": "2026-10-11 07:33:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "908e92a444cdc82ce182612d2f929eb2,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1941644": [
        {
            "ioc_value": "85.17.92.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 09:46:01",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941643": [
        {
            "ioc_value": "80.76.49.48:5050",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 09:45:56",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941642": [
        {
            "ioc_value": "46.246.6.15:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-29 09:45:40",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941641": [
        {
            "ioc_value": "45.127.32.150:57781",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-29 09:45:29",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941635": [
        {
            "ioc_value": "36.255.97.47:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-29 09:45:21",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941634": [
        {
            "ioc_value": "31.56.209.140:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-29 09:45:14",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941633": [
        {
            "ioc_value": "23.227.202.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-29 09:45:11",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941632": [
        {
            "ioc_value": "20.93.144.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 09:44:33",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941630": [
        {
            "ioc_value": "20.71.162.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 09:44:32",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941631": [
        {
            "ioc_value": "20.71.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 09:44:32",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941629": [
        {
            "ioc_value": "156.252.91.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-29 09:43:44",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941628": [
        {
            "ioc_value": "154.193.159.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-29 09:43:39",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941627": [
        {
            "ioc_value": "128.90.106.56:9786",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-29 09:43:22",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941626": [
        {
            "ioc_value": "104.207.88.70:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-29 09:43:11",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941605": [
        {
            "ioc_value": "153.80.242.105:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-29 08:21:52",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941597": [
        {
            "ioc_value": "46.19.140.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-29 08:05:06",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1941594": [
        {
            "ioc_value": "155.103.69.61:17508",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-29 07:50:51",
            "last_seen_utc": "2026-10-11 06:50:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/dc900bfbc7009b914a2064be4732533dc3a2210e5e9fd69bcd2482da5f3614c2/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941588": [
        {
            "ioc_value": "155.103.69.61:17509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-29 07:42:22",
            "last_seen_utc": "2026-10-11 06:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f4618b15a3e4e02aead52f828c905899262c794d825193352ac1ce1b71983378/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941561": [
        {
            "ioc_value": "38.9.96.236:2707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-29 07:15:55",
            "last_seen_utc": "2026-10-11 05:25:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,mkv V1 1new,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1941558": [
        {
            "ioc_value": "51.54.125.210:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 07:05:07",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1941557": [
        {
            "ioc_value": "187.145.62.206:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 07:05:05",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1941556": [
        {
            "ioc_value": "102.117.165.210:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-29 07:05:04",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1941250": [
        {
            "ioc_value": "94.154.40.119:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-29 06:28:39",
            "last_seen_utc": "2026-10-11 05:13:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,tor25t",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1941251": [
        {
            "ioc_value": "https://bh.32naga.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-29 06:28:38",
            "last_seen_utc": "2026-10-11 07:35:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,dd459308485752b72e79103d8df6ebbe,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1941252": [
        {
            "ioc_value": "https://pz.32naga.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-29 06:28:38",
            "last_seen_utc": "2026-10-11 07:36:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "2f18de214042c96f5cddd8c9b9563da6,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1941307": [
        {
            "ioc_value": "196.251.121.249:10213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.cecbot",
            "malware_alias": null,
            "malware_printable": "CECbot",
            "first_seen_utc": "2026-09-29 06:28:28",
            "last_seen_utc": "2026-10-10 23:44:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/cecbot",
            "tags": "android,botnet,cecbot,ddos",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1941205": [
        {
            "ioc_value": "94.154.32.44:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:56",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941204": [
        {
            "ioc_value": "94.130.72.248:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-28 19:46:55",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941202": [
        {
            "ioc_value": "91.92.41.40:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:52",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941203": [
        {
            "ioc_value": "91.92.41.40:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:52",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941201": [
        {
            "ioc_value": "91.92.41.40:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:51",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941199": [
        {
            "ioc_value": "72.51.59.132:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:34",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941200": [
        {
            "ioc_value": "72.51.59.132:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:34",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941198": [
        {
            "ioc_value": "64.94.85.173:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:46:31",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941197": [
        {
            "ioc_value": "62.60.155.33:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-28 19:46:28",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941196": [
        {
            "ioc_value": "51.54.125.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:46:23",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941195": [
        {
            "ioc_value": "50.114.179.215:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:22",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941194": [
        {
            "ioc_value": "45.88.91.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:15",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941193": [
        {
            "ioc_value": "45.152.242.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 19:46:07",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941192": [
        {
            "ioc_value": "45.139.104.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 19:46:04",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941191": [
        {
            "ioc_value": "36.255.97.47:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-28 19:45:54",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941190": [
        {
            "ioc_value": "34.116.132.157:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-28 19:45:52",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941183": [
        {
            "ioc_value": "20.234.176.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:44:56",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941184": [
        {
            "ioc_value": "20.93.144.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:44:56",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941181": [
        {
            "ioc_value": "20.160.224.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:44:55",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941182": [
        {
            "ioc_value": "20.160.224.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:44:55",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941180": [
        {
            "ioc_value": "177.22.117.0:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941179": [
        {
            "ioc_value": "172.245.106.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-28 19:44:10",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941178": [
        {
            "ioc_value": "163.172.248.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:44:04",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941177": [
        {
            "ioc_value": "156.252.91.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 19:43:56",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941176": [
        {
            "ioc_value": "154.86.96.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 19:43:53",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941175": [
        {
            "ioc_value": "125.75.36.126:40213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-28 19:43:27",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1941174": [
        {
            "ioc_value": "102.117.164.35:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940980": [
        {
            "ioc_value": "179.43.170.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-28 13:05:05",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1940949": [
        {
            "ioc_value": "144.172.69.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-28 12:05:07",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1940925": [
        {
            "ioc_value": "85.198.108.131:51227",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-28 10:45:51",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940924": [
        {
            "ioc_value": "83.136.210.2:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-28 10:45:49",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940923": [
        {
            "ioc_value": "80.190.77.86:20400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-28 10:45:45",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940922": [
        {
            "ioc_value": "52.197.194.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 10:45:35",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940920": [
        {
            "ioc_value": "36.248.232.190:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 10:45:12",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940921": [
        {
            "ioc_value": "36.255.97.47:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-28 10:45:12",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940919": [
        {
            "ioc_value": "217.60.195.193:56101",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 10:44:57",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940918": [
        {
            "ioc_value": "216.144.234.251:12897",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-09-28 10:44:54",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940917": [
        {
            "ioc_value": "206.209.210.6:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 10:44:31",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940916": [
        {
            "ioc_value": "172.86.80.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-28 10:43:56",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940909": [
        {
            "ioc_value": "154.193.158.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940910": [
        {
            "ioc_value": "154.193.158.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940911": [
        {
            "ioc_value": "154.193.158.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940912": [
        {
            "ioc_value": "154.193.158.239:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940913": [
        {
            "ioc_value": "154.193.158.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940914": [
        {
            "ioc_value": "154.193.160.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940915": [
        {
            "ioc_value": "154.193.160.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-28 10:43:40",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940908": [
        {
            "ioc_value": "15.152.249.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-28 10:43:37",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1940859": [
        {
            "ioc_value": "64.225.28.168:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-28 09:59:18",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/64.225.28.168#4321",
            "tags": "adaptix,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1940858": [
        {
            "ioc_value": "23.158.24.123:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-28 09:59:17",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/23.158.24.123#4321",
            "tags": "adaptix,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1940857": [
        {
            "ioc_value": "181.41.201.103:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-28 09:59:16",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/181.41.201.103#4321",
            "tags": "adaptix,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1940855": [
        {
            "ioc_value": "119.45.105.71:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-28 09:59:14",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.45.105.71#4321",
            "tags": "adaptix,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1940854": [
        {
            "ioc_value": "43.157.228.92:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-28 09:59:09",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/43.157.228.92#7443",
            "tags": "mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1940850": [
        {
            "ioc_value": "78.17.93.159:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-28 09:58:54",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/78.17.93.159#8090",
            "tags": "Havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1940822": [
        {
            "ioc_value": "203.202.232.117:2424",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-28 09:12:42",
            "last_seen_utc": "2026-10-11 05:34:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1940824": [
        {
            "ioc_value": "216.9.224.180:2444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-28 09:12:42",
            "last_seen_utc": "2026-10-11 05:05:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1939738": [
        {
            "ioc_value": "bbb.0101011010010111001.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-28 03:46:01",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939540": [
        {
            "ioc_value": "116.205.106.137:10051",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-27 20:14:14",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.205.106.137#10051",
            "tags": "cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1939519": [
        {
            "ioc_value": "82.25.12.111:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-27 19:45:39",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939514": [
        {
            "ioc_value": "31.77.138.10:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:45:03",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939512": [
        {
            "ioc_value": "217.60.103.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:44:49",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939509": [
        {
            "ioc_value": "195.177.94.156:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:44:19",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939510": [
        {
            "ioc_value": "195.177.94.156:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:44:19",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939508": [
        {
            "ioc_value": "185.213.22.64:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-27 19:44:03",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939507": [
        {
            "ioc_value": "18.218.117.239:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:43:58",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939506": [
        {
            "ioc_value": "169.58.38.91:7755",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-27 19:43:50",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939505": [
        {
            "ioc_value": "168.100.8.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:43:49",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939503": [
        {
            "ioc_value": "156.252.90.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-27 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939504": [
        {
            "ioc_value": "156.252.90.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-27 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939500": [
        {
            "ioc_value": "154.30.3.135:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939501": [
        {
            "ioc_value": "154.30.3.135:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939502": [
        {
            "ioc_value": "154.30.3.135:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939499": [
        {
            "ioc_value": "128.90.135.219:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-27 19:43:22",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939362": [
        {
            "ioc_value": "103.115.49.68:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-27 17:05:06",
            "last_seen_utc": "2026-10-11 09:19:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1939018": [
        {
            "ioc_value": "114.215.184.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-27 14:05:06",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1939016": [
        {
            "ioc_value": "38.190.196.25:5638",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-27 13:46:34",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939015": [
        {
            "ioc_value": "14.225.212.124:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-27 13:46:24",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939013": [
        {
            "ioc_value": "ns1.kcsc.tf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-27 13:46:14",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1939014": [
        {
            "ioc_value": "ns2.kcsc.tf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-27 13:46:14",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938992": [
        {
            "ioc_value": "xingyaotec.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-27 12:42:27",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1938710": [
        {
            "ioc_value": "89.125.66.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-27 09:45:55",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938709": [
        {
            "ioc_value": "80.76.49.48:7575",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 09:45:49",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938708": [
        {
            "ioc_value": "46.151.182.5:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-27 09:45:32",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938707": [
        {
            "ioc_value": "31.76.125.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-27 09:45:12",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938706": [
        {
            "ioc_value": "169.58.38.91:5552",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-27 09:43:54",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938704": [
        {
            "ioc_value": "169.58.38.91:3110",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-27 09:43:53",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938705": [
        {
            "ioc_value": "169.58.38.91:4466",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-27 09:43:53",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1938703": [
        {
            "ioc_value": "156.238.233.131:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-27 09:43:44",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935835": [
        {
            "ioc_value": "64.188.59.224:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-27 07:05:05",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1935590": [
        {
            "ioc_value": "xekong4power.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:17",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935592": [
        {
            "ioc_value": "yachtmaster.ro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:17",
            "last_seen_utc": "2026-10-09 17:11:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935578": [
        {
            "ioc_value": "way2hub.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:16",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935579": [
        {
            "ioc_value": "welchelelectrical.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:16",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935540": [
        {
            "ioc_value": "theburritocity.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:15",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935547": [
        {
            "ioc_value": "timecurrency.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:15",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935552": [
        {
            "ioc_value": "toussiplomberie.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:15",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935560": [
        {
            "ioc_value": "usakyazilim.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:15",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935519": [
        {
            "ioc_value": "sumalpe.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:14",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935527": [
        {
            "ioc_value": "tacheles-regional.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:14",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935528": [
        {
            "ioc_value": "tallerenantequera.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:14",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935529": [
        {
            "ioc_value": "tamladevent.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:14",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935534": [
        {
            "ioc_value": "techcrafter.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:14",
            "last_seen_utc": "2026-10-09 17:11:44",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935491": [
        {
            "ioc_value": "skegmc.org.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:01",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935501": [
        {
            "ioc_value": "spicymidia.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:01",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935468": [
        {
            "ioc_value": "rtlegalist.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935469": [
        {
            "ioc_value": "runforvaughan.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935473": [
        {
            "ioc_value": "samuyo.ca",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935474": [
        {
            "ioc_value": "sanpham.daitanphat.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935477": [
        {
            "ioc_value": "seal.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935481": [
        {
            "ioc_value": "sequum.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935483": [
        {
            "ioc_value": "sexfilmsdelen.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:57:00",
            "last_seen_utc": "2026-10-10 14:55:16",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935453": [
        {
            "ioc_value": "resolutions.group",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:59",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935460": [
        {
            "ioc_value": "ritanvi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:59",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935467": [
        {
            "ioc_value": "rozenlogistics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:59",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935432": [
        {
            "ioc_value": "povill.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:58",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935408": [
        {
            "ioc_value": "omoladegbemisola.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:21",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935410": [
        {
            "ioc_value": "oniris-ci.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:21",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935419": [
        {
            "ioc_value": "palletizers.co.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:21",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935424": [
        {
            "ioc_value": "pgcares.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:21",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935426": [
        {
            "ioc_value": "phytocopeia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:21",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935389": [
        {
            "ioc_value": "nadavira.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:20",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935397": [
        {
            "ioc_value": "nextfiler.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:20",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935401": [
        {
            "ioc_value": "nhaxinhplaza.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:20",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935361": [
        {
            "ioc_value": "mephhub.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:19",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935366": [
        {
            "ioc_value": "miss-marquise.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:19",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935368": [
        {
            "ioc_value": "mkcontracting.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:19",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935374": [
        {
            "ioc_value": "moniscomarineservices.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:19",
            "last_seen_utc": "2026-10-09 17:11:42",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935335": [
        {
            "ioc_value": "leveldigital.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:18",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935336": [
        {
            "ioc_value": "lnx.virzicarburanti.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:18",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935337": [
        {
            "ioc_value": "locationmovers.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:18",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935349": [
        {
            "ioc_value": "marhababd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:18",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935351": [
        {
            "ioc_value": "marsclubcadiz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:18",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935356": [
        {
            "ioc_value": "mbsrestorativecentre.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:18",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935315": [
        {
            "ioc_value": "kandocopies.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:17",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935319": [
        {
            "ioc_value": "kinghams-lr.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:17",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935321": [
        {
            "ioc_value": "kolkatatravelhub.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:17",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935326": [
        {
            "ioc_value": "lajpalimpex.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:17",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935331": [
        {
            "ioc_value": "leandroerlich.art",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:17",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935332": [
        {
            "ioc_value": "lemonvcnetwork.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:17",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935291": [
        {
            "ioc_value": "hueadn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935297": [
        {
            "ioc_value": "imforce.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935299": [
        {
            "ioc_value": "independentdeveloper.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935300": [
        {
            "ioc_value": "inesinsights.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935302": [
        {
            "ioc_value": "inisiar.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935304": [
        {
            "ioc_value": "irayaina.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935307": [
        {
            "ioc_value": "jennifensports.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935308": [
        {
            "ioc_value": "jjtyresandrecovery.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935309": [
        {
            "ioc_value": "joliegoldeg.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:16",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935276": [
        {
            "ioc_value": "grupnou.cat",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:15",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935281": [
        {
            "ioc_value": "hgoc.edu.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:15",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935242": [
        {
            "ioc_value": "extendedfamilyhomecarellc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:14",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935248": [
        {
            "ioc_value": "fedbakbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:14",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935252": [
        {
            "ioc_value": "finaldraft.co.in",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:14",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935255": [
        {
            "ioc_value": "flordeleche.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:14",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935258": [
        {
            "ioc_value": "fontenaylemarmion.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:14",
            "last_seen_utc": "2026-10-09 17:11:07",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935211": [
        {
            "ioc_value": "digital-tec.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935212": [
        {
            "ioc_value": "discombplacements.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935218": [
        {
            "ioc_value": "dulcesmartinez.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:56:00",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935182": [
        {
            "ioc_value": "communitywestrealestate.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935186": [
        {
            "ioc_value": "contentgate.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935191": [
        {
            "ioc_value": "creativemarketingsecrets.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935195": [
        {
            "ioc_value": "daghighsport.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935199": [
        {
            "ioc_value": "dawson-sports.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:59",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935159": [
        {
            "ioc_value": "businessplatform.whatswhat.ie",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:58",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935160": [
        {
            "ioc_value": "bytecubit.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:58",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935163": [
        {
            "ioc_value": "careers.cybereye.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:58",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935140": [
        {
            "ioc_value": "better-horse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935145": [
        {
            "ioc_value": "bluerockfinancing.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935146": [
        {
            "ioc_value": "bodrumgazetecilercemiyeti.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:57",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935152": [
        {
            "ioc_value": "brightfashionbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:57",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935114": [
        {
            "ioc_value": "alhayat.kz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:56",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935115": [
        {
            "ioc_value": "alladinshih-tzu.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:56",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935119": [
        {
            "ioc_value": "alsephinalodges.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:56",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935091": [
        {
            "ioc_value": "2rsolar.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-26 22:55:55",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1935033": [
        {
            "ioc_value": "64.89.161.92:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:56:52",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935032": [
        {
            "ioc_value": "31.56.209.161:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:54:07",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935031": [
        {
            "ioc_value": "217.60.77.60:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:51:33",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935030": [
        {
            "ioc_value": "213.252.232.182:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-26 19:48:07",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935029": [
        {
            "ioc_value": "195.177.94.227:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:46:11",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935028": [
        {
            "ioc_value": "185.94.29.158:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:45:50",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935027": [
        {
            "ioc_value": "185.254.99.169:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:45:46",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935026": [
        {
            "ioc_value": "176.149.202.136:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 19:45:32",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935024": [
        {
            "ioc_value": "173.249.56.221:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-26 19:44:20",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935023": [
        {
            "ioc_value": "154.18.239.166:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-26 19:43:55",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935022": [
        {
            "ioc_value": "153.75.251.188:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 19:43:54",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1935017": [
        {
            "ioc_value": "102.117.161.224:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-26 19:43:06",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934916": [
        {
            "ioc_value": "smartmindltd.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-26 16:33:00",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1934828": [
        {
            "ioc_value": "https://xx.234-e.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 15:32:09",
            "last_seen_utc": "2026-10-11 07:34:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "97a607fe4ad928b6d1096ccfa8de4e3d,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934812": [
        {
            "ioc_value": "143.244.190.5:5621",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-09-26 15:11:58",
            "last_seen_utc": "2026-10-09 16:54:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "RemusStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934804": [
        {
            "ioc_value": "https://hj.234-e.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 15:06:17",
            "last_seen_utc": "2026-10-11 07:34:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d10941da55166a8af5a9dd28a13ac9b5,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934792": [
        {
            "ioc_value": "39.98.120.223:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "vbs.vbrevshell",
            "malware_alias": null,
            "malware_printable": "VBREVSHELL",
            "first_seen_utc": "2026-09-26 14:36:13",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=39.98.120.223",
            "tags": "ViriBack,Vshell",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934793": [
        {
            "ioc_value": "8.133.234.121:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "vbs.vbrevshell",
            "malware_alias": null,
            "malware_printable": "VBREVSHELL",
            "first_seen_utc": "2026-09-26 14:36:13",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=8.133.234.121",
            "tags": "ViriBack,Vshell",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934791": [
        {
            "ioc_value": "47.105.68.108:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "vbs.vbrevshell",
            "malware_alias": null,
            "malware_printable": "VBREVSHELL",
            "first_seen_utc": "2026-09-26 14:36:02",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=47.105.68.108",
            "tags": "ViriBack,Vshell",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934785": [
        {
            "ioc_value": "23.160.168.51:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-09-26 14:12:02",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=23.160.168.51",
            "tags": "Overlord,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934778": [
        {
            "ioc_value": "23.238.82.42:3388",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-26 13:47:02",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934777": [
        {
            "ioc_value": "150.158.102.111:1235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-26 13:46:54",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934756": [
        {
            "ioc_value": "91.228.153.116:6886",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-26 12:46:43",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934755": [
        {
            "ioc_value": "89.106.83.214:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-09-26 12:46:41",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934754": [
        {
            "ioc_value": "57.182.163.105:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-09-26 12:46:27",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934753": [
        {
            "ioc_value": "46.151.182.5:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 12:46:20",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934752": [
        {
            "ioc_value": "209.126.103.97:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-26 12:45:00",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934751": [
        {
            "ioc_value": "193.161.193.99:63938",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 12:44:45",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934750": [
        {
            "ioc_value": "169.58.39.189:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-26 12:44:22",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934749": [
        {
            "ioc_value": "154.81.34.26:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-26 12:44:00",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934748": [
        {
            "ioc_value": "153.75.251.188:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 12:43:58",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934747": [
        {
            "ioc_value": "143.246.223.246:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-26 12:43:50",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934746": [
        {
            "ioc_value": "128.90.59.225:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 12:43:42",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934745": [
        {
            "ioc_value": "103.48.84.225:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 12:43:29",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934744": [
        {
            "ioc_value": "102.220.163.36:7008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-26 12:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934711": [
        {
            "ioc_value": "http://31.56.19.29/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-09-26 12:20:26",
            "last_seen_utc": "2026-10-11 09:10:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,Saif1,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934702": [
        {
            "ioc_value": "https://2.29.15.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:20:25",
            "last_seen_utc": "2026-10-11 09:50:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "89f97204cff0dbc175025ced3e9ff499,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934692": [
        {
            "ioc_value": "https://2.29.7.186",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:20:24",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,c4365025bf4905e4621f91972fe4429c,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934700": [
        {
            "ioc_value": "https://az.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:20:23",
            "last_seen_utc": "2026-10-11 07:34:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a40329ae164d29bf87ed3f80245b7fb1,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934703": [
        {
            "ioc_value": "https://bg.177betwin.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:20:23",
            "last_seen_utc": "2026-10-11 07:34:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "905052239b6df9bd7baab24dc3e50f49,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934683": [
        {
            "ioc_value": "https://ge.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:20:22",
            "last_seen_utc": "2026-10-11 07:34:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "061839e0c6a29ac1f895ba8d39fb0f78,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934707": [
        {
            "ioc_value": "https://ku.16dewaslot.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:20:21",
            "last_seen_utc": "2026-10-11 07:37:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,fa77cf3e42d5fa799429aa24c7f70a45,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934688": [
        {
            "ioc_value": "https://lb.334v.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:13",
            "last_seen_utc": "2026-10-11 07:37:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "26c683c10c410c36c2309a0d9d57d5c7,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934686": [
        {
            "ioc_value": "https://ms.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:12",
            "last_seen_utc": "2026-10-11 07:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,dad063e1b3e18547663d394a4a1b0ccf,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934687": [
        {
            "ioc_value": "https://nw.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:11",
            "last_seen_utc": "2026-10-11 07:44:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,fc99bd8607c97081de7780968727c206,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934729": [
        {
            "ioc_value": "https://nu.234-e.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:11",
            "last_seen_utc": "2026-10-11 07:47:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,cabc94c22ee1322a94ae30f7e787f859,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934710": [
        {
            "ioc_value": "https://nx.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:10",
            "last_seen_utc": "2026-10-11 07:44:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a49d5556ccfa93cdcdb7f001e04476e0,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934699": [
        {
            "ioc_value": "https://ze.zk89.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:08",
            "last_seen_utc": "2026-10-11 07:35:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "7cd64d42378edfb891c2791caca0f4cb,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934704": [
        {
            "ioc_value": "https://xx.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:08",
            "last_seen_utc": "2026-10-11 07:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0b705364e922593496da62f2c6e1174c,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934709": [
        {
            "ioc_value": "https://sm.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 12:13:08",
            "last_seen_utc": "2026-10-11 07:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,cea0c7054e603e996c91478c2d026ecb,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934725": [
        {
            "ioc_value": "https://95.217.241.133",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-26 10:16:15",
            "last_seen_utc": "2026-10-10 06:28:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "m0nk3,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934620": [
        {
            "ioc_value": "astrumsteel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-26 09:24:29",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1934624": [
        {
            "ioc_value": "celine-gronek.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-26 09:24:29",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1934534": [
        {
            "ioc_value": "46.250.228.119:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-26 08:05:21",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934533": [
        {
            "ioc_value": "209.38.82.85:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-26 08:05:13",
            "last_seen_utc": "2026-10-11 08:17:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932841": [
        {
            "ioc_value": "172.94.46.114:1014",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-26 06:20:49",
            "last_seen_utc": "2026-10-10 15:25:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934260": [
        {
            "ioc_value": "2.25.246.239:2466",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-26 06:20:26",
            "last_seen_utc": "2026-10-09 18:27:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,COLPro,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1934425": [
        {
            "ioc_value": "43.143.38.95:19999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-26 06:20:11",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1934500": [
        {
            "ioc_value": "178.253.31.5:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-26 03:47:05",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934348": [
        {
            "ioc_value": "84.21.189.110:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:47:04",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934347": [
        {
            "ioc_value": "45.59.170.162:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-25 19:46:33",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934346": [
        {
            "ioc_value": "45.254.246.140:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 19:46:32",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934344": [
        {
            "ioc_value": "38.240.49.89:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:46:15",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934343": [
        {
            "ioc_value": "34.51.203.250:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-25 19:46:10",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934341": [
        {
            "ioc_value": "31.56.209.161:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:46:01",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934342": [
        {
            "ioc_value": "31.56.209.161:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:46:01",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934340": [
        {
            "ioc_value": "31.56.209.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:46:00",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934331": [
        {
            "ioc_value": "212.86.125.129:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:45:13",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934332": [
        {
            "ioc_value": "212.86.125.129:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:45:13",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934330": [
        {
            "ioc_value": "192.227.153.89:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-25 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934329": [
        {
            "ioc_value": "177.22.116.3:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-25 19:44:20",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934328": [
        {
            "ioc_value": "158.94.210.177:2006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 19:44:01",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934327": [
        {
            "ioc_value": "156.236.76.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-25 19:43:56",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934326": [
        {
            "ioc_value": "154.92.252.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-25 19:43:55",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1934325": [
        {
            "ioc_value": "102.117.165.95:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-25 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932839": [
        {
            "ioc_value": "15.204.253.8:8239",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-09-25 14:10:10",
            "last_seen_utc": "2026-10-11 07:43:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RemusStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932831": [
        {
            "ioc_value": "indigo-finch-misgoaen.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-25 13:58:30",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1932772": [
        {
            "ioc_value": "99.92.203.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-25 09:47:29",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932771": [
        {
            "ioc_value": "45.128.156.112:56565",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-25 09:46:27",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932770": [
        {
            "ioc_value": "212.87.212.117:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-25 09:45:19",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932769": [
        {
            "ioc_value": "189.128.156.178:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-25 09:44:45",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932768": [
        {
            "ioc_value": "18.167.103.90:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-09-25 09:44:28",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932766": [
        {
            "ioc_value": "160.250.5.251:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-25 09:44:10",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932767": [
        {
            "ioc_value": "161.248.179.92:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:44:10",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932765": [
        {
            "ioc_value": "145.63.135.23:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:43:49",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932764": [
        {
            "ioc_value": "129.146.241.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-25 09:43:33",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932763": [
        {
            "ioc_value": "116.213.43.239:7891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-25 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932761": [
        {
            "ioc_value": "109.238.86.106:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:43:25",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932762": [
        {
            "ioc_value": "109.238.86.106:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:43:25",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932760": [
        {
            "ioc_value": "107.173.59.118:8580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:43:22",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932759": [
        {
            "ioc_value": "104.243.248.63:3601",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:43:17",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932758": [
        {
            "ioc_value": "102.220.163.36:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:43:10",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932749": [
        {
            "ioc_value": "23.132.164.72:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 09:05:04",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1932720": [
        {
            "ioc_value": "103.48.84.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 08:05:06",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1932471": [
        {
            "ioc_value": "43.156.187.96:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-25 06:28:11",
            "last_seen_utc": "2026-10-11 05:35:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1932506": [
        {
            "ioc_value": "176.126.114.42:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-25 06:28:10",
            "last_seen_utc": "2026-10-11 07:00:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1932689": [
        {
            "ioc_value": "103.48.84.225:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 06:05:10",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1932690": [
        {
            "ioc_value": "103.48.84.225:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-25 06:05:10",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1932682": [
        {
            "ioc_value": "42.51.44.173:18888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-25 05:47:58",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932661": [
        {
            "ioc_value": "45.227.253.132:56225",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-25 03:47:23",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932660": [
        {
            "ioc_value": "43.136.69.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-25 03:47:21",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932659": [
        {
            "ioc_value": "42.51.44.173:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-25 03:47:20",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932658": [
        {
            "ioc_value": "139.196.50.117:8839",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-25 03:47:07",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932657": [
        {
            "ioc_value": "i.gckni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-25 03:46:53",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932447": [
        {
            "ioc_value": "vale-quaiyn-jtbn8.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-24 20:40:49",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1932432": [
        {
            "ioc_value": "94.154.32.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:47:38",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932431": [
        {
            "ioc_value": "93.152.214.199:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-24 19:47:35",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932427": [
        {
            "ioc_value": "91.92.40.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:47:32",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932428": [
        {
            "ioc_value": "91.92.40.117:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:47:32",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932429": [
        {
            "ioc_value": "91.92.40.117:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:47:32",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932430": [
        {
            "ioc_value": "91.92.40.117:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:47:32",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932426": [
        {
            "ioc_value": "89.127.235.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-24 19:47:28",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932425": [
        {
            "ioc_value": "77.239.107.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:47:15",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932424": [
        {
            "ioc_value": "74.204.158.81:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 19:47:14",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932423": [
        {
            "ioc_value": "5.175.169.212:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-24 19:46:57",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932422": [
        {
            "ioc_value": "23.132.164.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932421": [
        {
            "ioc_value": "209.87.166.139:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:45:27",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932420": [
        {
            "ioc_value": "207.211.189.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-24 19:45:24",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932418": [
        {
            "ioc_value": "2.59.134.119:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:45:18",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932419": [
        {
            "ioc_value": "2.59.134.119:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:45:18",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932414": [
        {
            "ioc_value": "181.215.242.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932415": [
        {
            "ioc_value": "181.215.242.58:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932416": [
        {
            "ioc_value": "181.215.242.58:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932417": [
        {
            "ioc_value": "181.215.242.58:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932413": [
        {
            "ioc_value": "177.22.119.68:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-24 19:44:29",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932412": [
        {
            "ioc_value": "158.94.210.177:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 19:44:09",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932410": [
        {
            "ioc_value": "156.236.76.31:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:44:05",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932411": [
        {
            "ioc_value": "156.236.76.31:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:44:05",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932409": [
        {
            "ioc_value": "15.235.149.212:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:43:55",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932408": [
        {
            "ioc_value": "146.190.120.19:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-24 19:43:50",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932407": [
        {
            "ioc_value": "139.64.164.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:43:43",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932406": [
        {
            "ioc_value": "109.238.86.106:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 19:43:26",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932405": [
        {
            "ioc_value": "103.38.236.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932297": [
        {
            "ioc_value": "94.183.235.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-24 16:15:41",
            "last_seen_utc": "2026-10-10 15:17:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1932290": [
        {
            "ioc_value": "82.156.186.185:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 13:48:51",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932289": [
        {
            "ioc_value": "209.38.82.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 13:48:35",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932288": [
        {
            "ioc_value": "178-128-196-79.sslip.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 13:48:03",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932270": [
        {
            "ioc_value": "23.132.164.72:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 13:05:06",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1932247": [
        {
            "ioc_value": "84.38.133.167:7474",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-24 12:35:43",
            "last_seen_utc": "2026-10-11 04:10:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1932226": [
        {
            "ioc_value": "66.179.29.5:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 09:46:44",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932225": [
        {
            "ioc_value": "45.207.211.207:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-24 09:46:25",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932224": [
        {
            "ioc_value": "39.105.16.200:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-24 09:46:11",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932223": [
        {
            "ioc_value": "31.76.45.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-24 09:46:00",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932221": [
        {
            "ioc_value": "2.27.160.141:61712",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-24 09:44:56",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932220": [
        {
            "ioc_value": "188.212.158.203:1145",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 09:44:37",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932219": [
        {
            "ioc_value": "185.127.94.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-24 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932217": [
        {
            "ioc_value": "185.112.59.102:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 09:44:23",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932218": [
        {
            "ioc_value": "185.112.59.102:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 09:44:23",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932215": [
        {
            "ioc_value": "138.124.14.35:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-24 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932216": [
        {
            "ioc_value": "138.197.31.70:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-24 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932214": [
        {
            "ioc_value": "104.243.248.63:3606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 09:43:15",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932213": [
        {
            "ioc_value": "102.220.163.36:2505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-24 09:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1932209": [
        {
            "ioc_value": "155.103.71.242:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-24 09:11:10",
            "last_seen_utc": "2026-10-11 08:07:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Dragxcall00,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1931306": [
        {
            "ioc_value": "https://gt.234-e.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-24 08:07:24",
            "last_seen_utc": "2026-10-11 08:02:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e1b6418988f8ba8c0f55f99490d0591a,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1931310": [
        {
            "ioc_value": "155.103.69.57:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-24 08:07:23",
            "last_seen_utc": "2026-10-11 05:57:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,NewTrollxz,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1931305": [
        {
            "ioc_value": "102.117.173.122:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-24 07:05:08",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1931302": [
        {
            "ioc_value": "85.11.182.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 07:05:05",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1931251": [
        {
            "ioc_value": "101.35.217.145:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 04:05:10",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1931246": [
        {
            "ioc_value": "82.158.89.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 03:48:00",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931244": [
        {
            "ioc_value": "156.254.20.47:5996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 03:47:41",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931245": [
        {
            "ioc_value": "156.254.20.48:5996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 03:47:41",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931243": [
        {
            "ioc_value": "120.27.20.98:55801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-24 03:47:34",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931057": [
        {
            "ioc_value": "91.92.241.149:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:47:35",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931056": [
        {
            "ioc_value": "84.247.187.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:47:27",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931055": [
        {
            "ioc_value": "82.47.101.16:7000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:47:26",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931054": [
        {
            "ioc_value": "74.208.146.77:2244",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:47:18",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931053": [
        {
            "ioc_value": "37.244.231.39:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-23 19:46:28",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931052": [
        {
            "ioc_value": "31.77.220.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:46:25",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931051": [
        {
            "ioc_value": "23.160.168.167:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931050": [
        {
            "ioc_value": "202.146.222.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:45:19",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931049": [
        {
            "ioc_value": "2.59.134.119:56005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:45:17",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931048": [
        {
            "ioc_value": "2.26.29.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-23 19:45:15",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931047": [
        {
            "ioc_value": "195.177.94.29:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:45:08",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931046": [
        {
            "ioc_value": "195.177.94.29:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:45:07",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931045": [
        {
            "ioc_value": "195.177.94.16:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:45:06",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931044": [
        {
            "ioc_value": "192.253.229.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:44:54",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931043": [
        {
            "ioc_value": "192.177.26.195:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:44:52",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931042": [
        {
            "ioc_value": "192.159.99.211:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:44:50",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931041": [
        {
            "ioc_value": "185.241.211.244:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:44:40",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931040": [
        {
            "ioc_value": "184.75.208.66:46048",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931039": [
        {
            "ioc_value": "177.22.117.74:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-23 19:44:28",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931037": [
        {
            "ioc_value": "130.61.85.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-23 19:43:37",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931036": [
        {
            "ioc_value": "128.90.59.124:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1931035": [
        {
            "ioc_value": "128.90.112.84:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1930802": [
        {
            "ioc_value": "31.56.209.155:2407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 17:20:36",
            "last_seen_utc": "2026-10-10 13:12:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1929821": [
        {
            "ioc_value": "155.103.69.239:4551",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 15:47:48",
            "last_seen_utc": "2026-10-10 17:31:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,jardon,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1929824": [
        {
            "ioc_value": "155.103.69.239:4553",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 15:47:47",
            "last_seen_utc": "2026-10-10 17:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,jardon,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1930319": [
        {
            "ioc_value": "46.151.182.5:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 15:39:53",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/441519d53ac8fdea7b02de1941497c88aa7a3c6a23808ac1f985ce5155ded831/",
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929815": [
        {
            "ioc_value": "35.213.187.40:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-23 15:05:07",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1929666": [
        {
            "ioc_value": "102.117.167.58:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-23 14:05:07",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1929660": [
        {
            "ioc_value": "82.158.89.75:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-23 13:48:14",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929659": [
        {
            "ioc_value": "47.86.184.71:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-23 13:48:10",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929658": [
        {
            "ioc_value": "23.27.143.19:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-23 13:48:01",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929657": [
        {
            "ioc_value": "167.17.47.252:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-23 13:47:54",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929601": [
        {
            "ioc_value": "155.103.69.239:4550",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 10:53:01",
            "last_seen_utc": "2026-10-10 17:40:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,jardon,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1929595": [
        {
            "ioc_value": "8.137.111.232:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-23 09:46:57",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929594": [
        {
            "ioc_value": "64.227.178.198:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-23 09:46:48",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929593": [
        {
            "ioc_value": "51.159.21.191:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-23 09:46:41",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929592": [
        {
            "ioc_value": "47.243.96.54:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-23 09:46:37",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929590": [
        {
            "ioc_value": "velvet-otter-glagceis.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-23 09:45:10",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1929589": [
        {
            "ioc_value": "178.16.54.35:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-23 09:44:20",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929588": [
        {
            "ioc_value": "16.208.130.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 09:44:02",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929587": [
        {
            "ioc_value": "hollow-forge-rook-guiyn.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-23 09:44:01",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1929586": [
        {
            "ioc_value": "143.246.43.117:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 09:43:41",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929584": [
        {
            "ioc_value": "139.64.164.252:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929585": [
        {
            "ioc_value": "139.64.164.252:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929582": [
        {
            "ioc_value": "13.143.247.125:1458",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-23 09:43:31",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929583": [
        {
            "ioc_value": "13.143.247.125:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-23 09:43:31",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929580": [
        {
            "ioc_value": "120.27.155.171:50010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-23 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929581": [
        {
            "ioc_value": "121.127.233.190:7891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-23 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929579": [
        {
            "ioc_value": "104.250.167.93:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-23 09:43:17",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929578": [
        {
            "ioc_value": "104.243.248.63:3603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-23 09:43:15",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1929568": [
        {
            "ioc_value": "172.111.150.134:37690",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 09:02:39",
            "last_seen_utc": "2026-10-11 04:12:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/03928b404506908d14a05afbfdd11cc4eae0b2ce3e093cd6d9da5687453793c4/",
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927695": [
        {
            "ioc_value": "196.251.121.250:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 06:38:13",
            "last_seen_utc": "2026-10-11 05:37:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1928086": [
        {
            "ioc_value": "31.56.209.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 06:35:23",
            "last_seen_utc": "2026-10-11 00:51:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1928087": [
        {
            "ioc_value": "31.56.209.155:2405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 06:35:21",
            "last_seen_utc": "2026-10-10 13:27:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1928408": [
        {
            "ioc_value": "31.56.209.155:9987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-23 06:34:13",
            "last_seen_utc": "2026-10-11 00:48:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1928356": [
        {
            "ioc_value": "114.66.27.110:60010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-23 03:47:37",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1928043": [
        {
            "ioc_value": "142.93.126.132:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 22:05:07",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1928044": [
        {
            "ioc_value": "143.244.135.17:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 22:05:07",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1928030": [
        {
            "ioc_value": "88.119.174.86:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 21:47:45",
            "last_seen_utc": "2026-10-11 09:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1928029": [
        {
            "ioc_value": "barthvertex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 21:47:07",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1928009": [
        {
            "ioc_value": "175.124.145.102:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 21:05:07",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1927932": [
        {
            "ioc_value": "93.152.214.28:7222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:47:10",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927930": [
        {
            "ioc_value": "45.88.91.54:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:46:30",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927929": [
        {
            "ioc_value": "31.77.220.78:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:46:04",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927928": [
        {
            "ioc_value": "216.250.253.197:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:45:43",
            "last_seen_utc": "2026-10-11 09:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927927": [
        {
            "ioc_value": "20.93.144.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 19:45:00",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927922": [
        {
            "ioc_value": "191.223.34.61:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:39",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927919": [
        {
            "ioc_value": "191.107.92.58:5012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-22 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927920": [
        {
            "ioc_value": "191.223.33.20:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927921": [
        {
            "ioc_value": "191.223.34.57:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927918": [
        {
            "ioc_value": "178.94.25.230:8902",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-22 19:44:20",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927917": [
        {
            "ioc_value": "172.94.9.194:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927916": [
        {
            "ioc_value": "172.93.161.96:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927913": [
        {
            "ioc_value": "172.252.225.151:12688",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-22 19:44:13",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927914": [
        {
            "ioc_value": "172.252.225.152:12688",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-22 19:44:13",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927915": [
        {
            "ioc_value": "172.252.225.153:12688",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-22 19:44:13",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927912": [
        {
            "ioc_value": "167.94.47.130:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:08",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927911": [
        {
            "ioc_value": "162.33.177.101:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-22 19:44:05",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927910": [
        {
            "ioc_value": "160.250.181.159:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:03",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927909": [
        {
            "ioc_value": "160.250.181.159:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:44:01",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927907": [
        {
            "ioc_value": "130.61.146.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-09-22 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927908": [
        {
            "ioc_value": "130.61.146.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-09-22 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927905": [
        {
            "ioc_value": "13.127.122.166:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 19:43:30",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927906": [
        {
            "ioc_value": "13.143.247.124:1881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:43:30",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927904": [
        {
            "ioc_value": "109.74.144.151:46321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-22 19:43:23",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927903": [
        {
            "ioc_value": "104.37.174.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 19:43:17",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927902": [
        {
            "ioc_value": "104.131.163.233:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-22 19:43:13",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927901": [
        {
            "ioc_value": "102.220.163.36:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-22 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927900": [
        {
            "ioc_value": "102.117.163.135:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927873": [
        {
            "ioc_value": "146.190.111.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 19:05:06",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1927661": [
        {
            "ioc_value": "growwgroup.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927662": [
        {
            "ioc_value": "grupotahona.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927663": [
        {
            "ioc_value": "lararecovery.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927664": [
        {
            "ioc_value": "maalaitimes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927667": [
        {
            "ioc_value": "n42technology.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927668": [
        {
            "ioc_value": "nighttidemultimedia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927669": [
        {
            "ioc_value": "proba.agotaeskuvoszervezes.hu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927670": [
        {
            "ioc_value": "shinewithnishi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927671": [
        {
            "ioc_value": "skandllc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927672": [
        {
            "ioc_value": "suoloenergia.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927674": [
        {
            "ioc_value": "wayakhotelnic.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927675": [
        {
            "ioc_value": "www.caycanhdep.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:40",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927657": [
        {
            "ioc_value": "alesecream.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 17:45:39",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hw-token",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927644": [
        {
            "ioc_value": "31.56.209.155:2406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-22 17:37:53",
            "last_seen_utc": "2026-10-10 19:02:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1927647": [
        {
            "ioc_value": "31.56.209.155:3398",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-22 17:37:53",
            "last_seen_utc": "2026-10-10 19:05:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1927640": [
        {
            "ioc_value": "31.56.209.155:2409",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-22 17:29:25",
            "last_seen_utc": "2026-10-11 00:39:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RIOTMEDIC2026CRYPTOSCREENSHOT",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1927631": [
        {
            "ioc_value": "45.225.135.115:4356",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-22 17:21:35",
            "last_seen_utc": "2026-10-11 07:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1927536": [
        {
            "ioc_value": "cirkoborpi.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-22 16:28:06",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1927492": [
        {
            "ioc_value": "60.217.23.146:7789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 15:48:08",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927376": [
        {
            "ioc_value": "91.92.47.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 13:48:28",
            "last_seen_utc": "2026-10-11 09:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927375": [
        {
            "ioc_value": "175.124.145.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 13:48:08",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927374": [
        {
            "ioc_value": "141.255.162.236:37422",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 13:48:02",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927373": [
        {
            "ioc_value": "123.207.214.140:6322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 13:47:59",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927372": [
        {
            "ioc_value": "123.207.214.140:6321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 13:47:58",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927371": [
        {
            "ioc_value": "meritphilips.fans",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 13:47:44",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927343": [
        {
            "ioc_value": "139.99.88.62:3778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-09-22 12:18:54",
            "last_seen_utc": "2026-10-10 08:28:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://tria.ge/260922-gzfa6ahf99/behavioral1",
            "tags": "XWorm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927301": [
        {
            "ioc_value": "84.200.91.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:47:17",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927300": [
        {
            "ioc_value": "5.175.169.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:46:52",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927299": [
        {
            "ioc_value": "46.40.193.169:1723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-22 09:46:50",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927298": [
        {
            "ioc_value": "46.246.84.6:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-22 09:46:49",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927297": [
        {
            "ioc_value": "41.68.226.249:5554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-22 09:46:27",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927295": [
        {
            "ioc_value": "34.87.129.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 09:46:19",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927296": [
        {
            "ioc_value": "36.248.232.160:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-22 09:46:19",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927291": [
        {
            "ioc_value": "217.60.195.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:46:00",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927292": [
        {
            "ioc_value": "217.60.195.60:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:46:00",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927293": [
        {
            "ioc_value": "217.60.195.60:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:46:00",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927294": [
        {
            "ioc_value": "217.60.195.60:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:46:00",
            "last_seen_utc": "2026-10-11 09:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927290": [
        {
            "ioc_value": "193.143.1.247:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-22 09:44:45",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927289": [
        {
            "ioc_value": "192.142.10.165:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-22 09:44:40",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927288": [
        {
            "ioc_value": "188.48.121.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-22 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927287": [
        {
            "ioc_value": "188.137.227.133:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-22 09:44:38",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927286": [
        {
            "ioc_value": "13.143.247.204:4810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:43:31",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927285": [
        {
            "ioc_value": "121.41.70.79:9966",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-22 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927284": [
        {
            "ioc_value": "104.168.148.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-22 09:43:14",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927265": [
        {
            "ioc_value": "47.114.83.19:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 08:35:13",
            "last_seen_utc": "2026-10-11 08:17:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1927250": [
        {
            "ioc_value": "111.230.37.219:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 08:05:05",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1927208": [
        {
            "ioc_value": "http://178.16.54.165/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-09-22 06:39:09",
            "last_seen_utc": "2026-10-11 09:48:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "21Sept,c2,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1927211": [
        {
            "ioc_value": "149.88.73.83:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 06:05:07",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1926843": [
        {
            "ioc_value": "2.27.62.228:60201",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-22 05:00:06",
            "last_seen_utc": "2026-10-11 08:04:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1927119": [
        {
            "ioc_value": "60.217.23.146:7788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-22 03:48:15",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926809": [
        {
            "ioc_value": "84.32.41.19:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:46:55",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926808": [
        {
            "ioc_value": "72.83.221.122:2284",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-21 19:46:45",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926807": [
        {
            "ioc_value": "66.179.29.5:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:46:42",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926806": [
        {
            "ioc_value": "46.151.182.67:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:46:27",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926805": [
        {
            "ioc_value": "38.60.136.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-21 19:46:09",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926803": [
        {
            "ioc_value": "31.56.209.139:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:45:55",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926804": [
        {
            "ioc_value": "31.56.209.139:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:45:55",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926801": [
        {
            "ioc_value": "193.112.254.32:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-21 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926800": [
        {
            "ioc_value": "188.120.255.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:44:36",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926799": [
        {
            "ioc_value": "177.5.67.246:55443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-21 19:44:18",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926798": [
        {
            "ioc_value": "149.56.206.68:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-21 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926796": [
        {
            "ioc_value": "147.93.191.75:40100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-21 19:43:46",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926797": [
        {
            "ioc_value": "149.104.78.139:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-21 19:43:46",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926794": [
        {
            "ioc_value": "134.19.177.62:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926795": [
        {
            "ioc_value": "134.19.177.62:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926793": [
        {
            "ioc_value": "13.140.145.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-21 19:43:30",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926792": [
        {
            "ioc_value": "128.90.135.172:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-21 19:43:28",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926791": [
        {
            "ioc_value": "104.64.208.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 19:43:16",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926491": [
        {
            "ioc_value": "78.17.212.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-21 13:48:25",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926490": [
        {
            "ioc_value": "45.227.253.132:56223",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-21 13:48:21",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926393": [
        {
            "ioc_value": "88.119.169.135:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-21 09:47:07",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926392": [
        {
            "ioc_value": "54.244.240.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-21 09:46:43",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926390": [
        {
            "ioc_value": "52.47.77.229:1999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-21 09:46:42",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926391": [
        {
            "ioc_value": "52.47.77.229:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-21 09:46:42",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926389": [
        {
            "ioc_value": "45.86.229.111:40062",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-21 09:46:32",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926388": [
        {
            "ioc_value": "45.202.1.16:14501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-21 09:46:29",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926387": [
        {
            "ioc_value": "45.152.242.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-21 09:46:23",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926386": [
        {
            "ioc_value": "37.220.31.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-09-21 09:46:09",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926385": [
        {
            "ioc_value": "31.77.12.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-09-21 09:46:06",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926384": [
        {
            "ioc_value": "23.158.24.65:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-21 09:45:54",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926383": [
        {
            "ioc_value": "194.49.68.166:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-21 09:44:49",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926382": [
        {
            "ioc_value": "192.236.166.73:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-21 09:44:44",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926381": [
        {
            "ioc_value": "185.212.128.89:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-21 09:44:30",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926380": [
        {
            "ioc_value": "15.235.149.212:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-21 09:43:49",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926379": [
        {
            "ioc_value": "13.232.187.232:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-21 09:43:31",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926157": [
        {
            "ioc_value": "193.178.158.107:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-09-21 00:36:02",
            "last_seen_utc": "2026-10-11 09:48:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=193.178.158.107",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926149": [
        {
            "ioc_value": "81.70.21.163:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-21 00:05:05",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1926022": [
        {
            "ioc_value": "95.182.91.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-20 19:47:28",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926023": [
        {
            "ioc_value": "96.126.176.243:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-20 19:47:28",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926021": [
        {
            "ioc_value": "52.47.77.229:2000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 19:46:49",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926020": [
        {
            "ioc_value": "5.180.20.26:13213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-20 19:46:46",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926019": [
        {
            "ioc_value": "5.175.169.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-20 19:46:45",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926018": [
        {
            "ioc_value": "46.151.182.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-20 19:46:41",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926017": [
        {
            "ioc_value": "154.86.105.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-20 19:43:56",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926016": [
        {
            "ioc_value": "130.94.66.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-20 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926015": [
        {
            "ioc_value": "102.220.163.36:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1926014": [
        {
            "ioc_value": "102.117.165.17:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-20 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1925903": [
        {
            "ioc_value": "https://xd.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-20 16:36:19",
            "last_seen_utc": "2026-10-11 07:56:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "061839e0c6a29ac1f895ba8d39fb0f78,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1925881": [
        {
            "ioc_value": "https://oi.hg77.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-20 14:52:20",
            "last_seen_utc": "2026-10-11 07:39:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,fc99bd8607c97081de7780968727c206,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1924863": [
        {
            "ioc_value": "94.183.235.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-20 14:52:16",
            "last_seen_utc": "2026-10-11 02:33:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1924864": [
        {
            "ioc_value": "94.183.235.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-20 14:52:16",
            "last_seen_utc": "2026-10-11 01:33:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1924865": [
        {
            "ioc_value": "94.183.235.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-20 14:52:15",
            "last_seen_utc": "2026-10-10 15:17:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1924906": [
        {
            "ioc_value": "http://193.178.158.107/Bjsw3DlG1/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-09-20 14:52:03",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "579cd0,amadey,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1924904": [
        {
            "ioc_value": "62.164.177.14:22235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-20 13:48:14",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924903": [
        {
            "ioc_value": "209.99.186.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-20 13:48:03",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924902": [
        {
            "ioc_value": "complianceportals.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-20 13:47:35",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924840": [
        {
            "ioc_value": "89.153.179.188:24996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:47:32",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924839": [
        {
            "ioc_value": "46.36.40.185:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-20 09:46:57",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924837": [
        {
            "ioc_value": "45.88.91.165:7590",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-20 09:46:53",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924836": [
        {
            "ioc_value": "45.139.104.26:55012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-20 09:46:40",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924833": [
        {
            "ioc_value": "36.248.232.184:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-20 09:46:27",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924832": [
        {
            "ioc_value": "194.26.192.153:2002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:56",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924831": [
        {
            "ioc_value": "185.34.147.35:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:45",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924830": [
        {
            "ioc_value": "185.34.147.34:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:44",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924829": [
        {
            "ioc_value": "185.34.147.33:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:43",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924828": [
        {
            "ioc_value": "185.34.147.32:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924826": [
        {
            "ioc_value": "185.34.147.31:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924827": [
        {
            "ioc_value": "185.34.147.32:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924825": [
        {
            "ioc_value": "185.34.147.31:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:44:40",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924824": [
        {
            "ioc_value": "132.226.198.241:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-20 09:43:37",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924823": [
        {
            "ioc_value": "128.90.59.115:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-20 09:43:33",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924822": [
        {
            "ioc_value": "128.241.244.7:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-20 09:43:31",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924821": [
        {
            "ioc_value": "101.42.33.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-20 09:43:03",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924810": [
        {
            "ioc_value": "47.116.130.234:82",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-20 08:29:11",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924809": [
        {
            "ioc_value": "116.62.174.16:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-20 08:29:10",
            "last_seen_utc": "2026-10-11 08:17:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924685": [
        {
            "ioc_value": "161.248.179.24:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-20 05:32:54",
            "last_seen_utc": "2026-10-11 09:07:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1924763": [
        {
            "ioc_value": "81.70.21.163:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-20 03:47:59",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924672": [
        {
            "ioc_value": "94.154.32.189:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:48:17",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924670": [
        {
            "ioc_value": "94.154.32.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:48:16",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924671": [
        {
            "ioc_value": "94.154.32.189:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:48:16",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924669": [
        {
            "ioc_value": "91.92.241.149:90",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 19:48:08",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924666": [
        {
            "ioc_value": "89.106.83.225:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:48:04",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924667": [
        {
            "ioc_value": "89.106.83.225:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:48:04",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924668": [
        {
            "ioc_value": "89.106.83.225:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:48:04",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924665": [
        {
            "ioc_value": "67.43.56.25:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 19:47:44",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924664": [
        {
            "ioc_value": "64.89.161.92:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:47:40",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924663": [
        {
            "ioc_value": "51.222.87.92:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-19 19:47:30",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924662": [
        {
            "ioc_value": "5.230.155.140:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:47:28",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924661": [
        {
            "ioc_value": "45.88.91.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:47:21",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924660": [
        {
            "ioc_value": "45.139.104.26:56016",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:47:07",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924658": [
        {
            "ioc_value": "43.135.26.173:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:47:01",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924659": [
        {
            "ioc_value": "43.135.26.173:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:47:01",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924657": [
        {
            "ioc_value": "31.56.209.53:5353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:46:42",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924655": [
        {
            "ioc_value": "31.56.209.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:46:41",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924656": [
        {
            "ioc_value": "31.56.209.139:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 19:46:41",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924654": [
        {
            "ioc_value": "194.32.114.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-19 19:45:19",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924653": [
        {
            "ioc_value": "186.244.214.231:56672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-19 19:44:59",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924652": [
        {
            "ioc_value": "176.149.202.136:8807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 19:44:39",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924651": [
        {
            "ioc_value": "128.90.112.200:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-19 19:43:36",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924650": [
        {
            "ioc_value": "104.243.248.63:3604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 19:43:18",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924649": [
        {
            "ioc_value": "104.207.132.238:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-19 19:43:16",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924620": [
        {
            "ioc_value": "42.193.238.29:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 17:48:49",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924589": [
        {
            "ioc_value": "154.219.101.56:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 15:48:38",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924506": [
        {
            "ioc_value": "177.5.67.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 13:48:22",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924505": [
        {
            "ioc_value": "156.238.233.131:50022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 13:48:20",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924504": [
        {
            "ioc_value": "106.53.168.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 13:48:07",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924503": [
        {
            "ioc_value": "api.microsoftstorapi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 13:47:56",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924425": [
        {
            "ioc_value": "42.193.169.176:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 09:47:56",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924423": [
        {
            "ioc_value": "91.92.241.149:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 09:47:12",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924424": [
        {
            "ioc_value": "91.92.241.149:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 09:47:12",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924422": [
        {
            "ioc_value": "64.84.56.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-19 09:46:50",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924420": [
        {
            "ioc_value": "217.60.195.193:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 09:45:53",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924421": [
        {
            "ioc_value": "217.60.195.193:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 09:45:53",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924419": [
        {
            "ioc_value": "217.60.195.193:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-19 09:45:52",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924418": [
        {
            "ioc_value": "209.38.224.48:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-19 09:45:09",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924417": [
        {
            "ioc_value": "188.137.227.133:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 09:44:37",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924416": [
        {
            "ioc_value": "181.206.118.219:5118",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-19 09:44:23",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924415": [
        {
            "ioc_value": "154.86.14.17:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-19 09:43:54",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924414": [
        {
            "ioc_value": "154.216.139.17:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-19 09:43:53",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924413": [
        {
            "ioc_value": "146.70.51.74:2512",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-19 09:43:43",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924412": [
        {
            "ioc_value": "138.0.191.215:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-19 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924411": [
        {
            "ioc_value": "137.184.139.185:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-09-19 09:43:35",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924408": [
        {
            "ioc_value": "128.241.244.3:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-19 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924409": [
        {
            "ioc_value": "128.241.244.3:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-19 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924410": [
        {
            "ioc_value": "128.241.244.7:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-19 09:43:28",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924407": [
        {
            "ioc_value": "102.220.160.198:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-19 09:43:06",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924399": [
        {
            "ioc_value": "101.34.208.175:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 09:19:03",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924396": [
        {
            "ioc_value": "123.57.146.34:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 09:18:59",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924393": [
        {
            "ioc_value": "kiln-skioi-c29up.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-19 09:06:06",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1924394": [
        {
            "ioc_value": "trilliot6776.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-19 09:06:06",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1924357": [
        {
            "ioc_value": "https://ma.1hoki.org",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-19 06:25:37",
            "last_seen_utc": "2026-10-11 07:39:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "bf33027f37759641887481194ff9b944,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1924325": [
        {
            "ioc_value": "https://192.142.37.129",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-19 05:52:21",
            "last_seen_utc": "2026-10-11 09:48:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "7347836807ad35a478daa982b6a56e60,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1924323": [
        {
            "ioc_value": "167.179.67.162:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-19 03:47:32",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924215": [
        {
            "ioc_value": "94.154.43.211:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-18 19:47:06",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924214": [
        {
            "ioc_value": "92.118.126.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:47:01",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924213": [
        {
            "ioc_value": "91.219.239.100:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:57",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924212": [
        {
            "ioc_value": "80.190.77.86:1003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-18 19:46:45",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924211": [
        {
            "ioc_value": "64.89.161.92:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:38",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924210": [
        {
            "ioc_value": "62.233.51.136:7222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:35",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924209": [
        {
            "ioc_value": "45.88.186.207:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:23",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924207": [
        {
            "ioc_value": "45.192.211.126:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:16",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924208": [
        {
            "ioc_value": "45.192.211.126:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:16",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924205": [
        {
            "ioc_value": "45.139.104.26:55010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924206": [
        {
            "ioc_value": "45.139.104.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924204": [
        {
            "ioc_value": "23.94.197.13:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-18 19:45:48",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924203": [
        {
            "ioc_value": "209.74.86.250:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-18 19:44:57",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924201": [
        {
            "ioc_value": "193.25.215.83:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924202": [
        {
            "ioc_value": "193.26.115.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924200": [
        {
            "ioc_value": "185.212.128.32:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-18 19:44:21",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924199": [
        {
            "ioc_value": "176.65.132.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-18 19:44:14",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924198": [
        {
            "ioc_value": "172.86.85.185:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-18 19:44:10",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924197": [
        {
            "ioc_value": "167.99.174.8:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-18 19:44:02",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924196": [
        {
            "ioc_value": "157.230.7.115:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-18 19:43:53",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924195": [
        {
            "ioc_value": "149.88.76.74:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:43:43",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924194": [
        {
            "ioc_value": "147.124.214.219:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 19:43:41",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924193": [
        {
            "ioc_value": "13.193.175.186:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-09-18 19:43:27",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1924109": [
        {
            "ioc_value": "82.29.92.60:35121",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-18 18:19:57",
            "last_seen_utc": "2026-10-11 08:40:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260918-sh2cvage92",
            "tags": "Remcos",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1924001": [
        {
            "ioc_value": "https://ma.zk89.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-18 17:23:47",
            "last_seen_utc": "2026-10-11 07:39:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d11f5c04051e332b9cfaabcb37c2ada9,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1923959": [
        {
            "ioc_value": "36.255.97.162:4045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-18 13:48:42",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923917": [
        {
            "ioc_value": "206.123.137.132:57484",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-18 13:17:45",
            "last_seen_utc": "2026-10-11 08:26:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Port$$,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1923944": [
        {
            "ioc_value": "62.60.226.173:10213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.cecbot",
            "malware_alias": null,
            "malware_printable": "CECbot",
            "first_seen_utc": "2026-09-18 13:17:38",
            "last_seen_utc": "2026-10-10 13:31:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/cecbot",
            "tags": "android,botnet,cecbot,ddos",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1923913": [
        {
            "ioc_value": "gaezskoynbrisk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-18 11:08:56",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1923886": [
        {
            "ioc_value": "80.76.49.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 09:57:46",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923885": [
        {
            "ioc_value": "5.163.239.119:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-18 09:57:14",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923884": [
        {
            "ioc_value": "46.246.6.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-18 09:57:09",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923882": [
        {
            "ioc_value": "45.202.0.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-18 09:56:59",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923883": [
        {
            "ioc_value": "45.202.0.55:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-18 09:56:59",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923880": [
        {
            "ioc_value": "45.139.104.222:55006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 09:56:47",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923881": [
        {
            "ioc_value": "45.139.104.26:55011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 09:56:47",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923879": [
        {
            "ioc_value": "45.139.104.222:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-18 09:56:46",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923878": [
        {
            "ioc_value": "38.242.209.29:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-18 09:56:36",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923876": [
        {
            "ioc_value": "2.56.97.65:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-18 09:44:48",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923875": [
        {
            "ioc_value": "191.107.92.58:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-18 09:44:29",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923874": [
        {
            "ioc_value": "144.31.148.132:45051",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-09-18 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923872": [
        {
            "ioc_value": "109.205.212.241:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-18 09:43:22",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923853": [
        {
            "ioc_value": "81.70.21.163:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-18 08:03:15",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-305419896",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923463": [
        {
            "ioc_value": "92.118.126.165:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:47:17",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923464": [
        {
            "ioc_value": "92.118.126.165:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:47:17",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923465": [
        {
            "ioc_value": "92.118.126.165:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:47:17",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923461": [
        {
            "ioc_value": "89.126.221.170:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-17 19:47:11",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923462": [
        {
            "ioc_value": "89.126.221.216:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-17 19:47:11",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923460": [
        {
            "ioc_value": "45.156.87.134:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:46:30",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923459": [
        {
            "ioc_value": "23.94.197.128:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-17 19:46:05",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923457": [
        {
            "ioc_value": "217.60.195.50:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:45:58",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923458": [
        {
            "ioc_value": "217.60.195.50:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:45:58",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923456": [
        {
            "ioc_value": "217.60.195.160:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:45:56",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923454": [
        {
            "ioc_value": "217.156.66.203:50604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:45:53",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923455": [
        {
            "ioc_value": "217.216.34.133:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-17 19:45:53",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923453": [
        {
            "ioc_value": "20.175.26.173:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-17 19:45:12",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923452": [
        {
            "ioc_value": "192.162.199.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:44:47",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923451": [
        {
            "ioc_value": "185.247.211.21:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:44:39",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923449": [
        {
            "ioc_value": "176.96.137.11:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:44:26",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923450": [
        {
            "ioc_value": "176.96.137.11:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:44:26",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923447": [
        {
            "ioc_value": "172.169.251.53:6160",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-17 19:44:16",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923446": [
        {
            "ioc_value": "149.88.76.74:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:43:49",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923444": [
        {
            "ioc_value": "147.124.199.248:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923445": [
        {
            "ioc_value": "147.224.179.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-17 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923441": [
        {
            "ioc_value": "147.124.199.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:43:46",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923442": [
        {
            "ioc_value": "147.124.199.248:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:43:46",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923443": [
        {
            "ioc_value": "147.124.199.248:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:43:46",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923439": [
        {
            "ioc_value": "132.243.221.34:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 19:43:35",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923438": [
        {
            "ioc_value": "128.90.136.246:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923437": [
        {
            "ioc_value": "109.205.212.241:45600",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-17 19:43:24",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923436": [
        {
            "ioc_value": "102.220.163.36:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923435": [
        {
            "ioc_value": "102.117.163.68:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-17 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923322": [
        {
            "ioc_value": "188.166.254.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-17 16:05:06",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1923320": [
        {
            "ioc_value": "189.141.53.203:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-17 16:05:05",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1923186": [
        {
            "ioc_value": "49.232.21.222:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 13:50:39",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923185": [
        {
            "ioc_value": "154.219.101.56:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 13:50:16",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923184": [
        {
            "ioc_value": "119.29.98.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 13:50:09",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923082": [
        {
            "ioc_value": "94.183.235.121:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-17 09:48:49",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923081": [
        {
            "ioc_value": "93.186.38.135:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-09-17 09:48:45",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923080": [
        {
            "ioc_value": "64.181.194.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-17 09:48:11",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923079": [
        {
            "ioc_value": "45.207.241.47:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-17 09:47:45",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923078": [
        {
            "ioc_value": "45.112.206.54:55005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-17 09:47:32",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923077": [
        {
            "ioc_value": "4.231.16.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-17 09:47:28",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923076": [
        {
            "ioc_value": "31.56.209.53:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 09:47:09",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923075": [
        {
            "ioc_value": "217.156.66.203:3609",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 09:46:50",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923074": [
        {
            "ioc_value": "209.99.188.193:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-17 09:46:04",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923073": [
        {
            "ioc_value": "209.38.100.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-17 09:46:01",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923072": [
        {
            "ioc_value": "194.26.192.153:2001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 09:45:34",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923070": [
        {
            "ioc_value": "172.86.91.14:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923071": [
        {
            "ioc_value": "172.86.91.14:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923069": [
        {
            "ioc_value": "172.111.139.65:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-17 09:44:31",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923068": [
        {
            "ioc_value": "159.198.32.64:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-17 09:44:19",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923067": [
        {
            "ioc_value": "15.235.149.212:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 09:43:59",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923065": [
        {
            "ioc_value": "147.124.202.216:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 09:43:56",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923066": [
        {
            "ioc_value": "147.124.202.216:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 09:43:56",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923064": [
        {
            "ioc_value": "128.90.105.123:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-17 09:43:37",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923062": [
        {
            "ioc_value": "122.51.212.92:39904",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-17 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923063": [
        {
            "ioc_value": "124.198.131.60:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-17 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923061": [
        {
            "ioc_value": "109.205.212.241:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-17 09:43:30",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923060": [
        {
            "ioc_value": "104.243.248.63:407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 09:43:19",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923059": [
        {
            "ioc_value": "102.220.163.36:2504",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-17 09:43:09",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1923058": [
        {
            "ioc_value": "102.188.200.238:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-17 09:43:06",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1922592": [
        {
            "ioc_value": "117.72.202.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 08:14:19",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921389": [
        {
            "ioc_value": "103.67.163.201:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-17 05:41:55",
            "last_seen_utc": "2026-10-11 06:02:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1921417": [
        {
            "ioc_value": "94.154.43.235:10213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.cecbot",
            "malware_alias": null,
            "malware_printable": "CECbot",
            "first_seen_utc": "2026-09-17 05:41:44",
            "last_seen_utc": "2026-10-11 02:27:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/cecbot",
            "tags": "android,botnet,cecbot,ddos",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1921459": [
        {
            "ioc_value": "http://91.92.242.57/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-09-17 05:41:36",
            "last_seen_utc": "2026-10-11 09:11:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,hurimurib3,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1921458": [
        {
            "ioc_value": "45.192.248.45:4431",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 03:48:22",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921457": [
        {
            "ioc_value": "45.192.248.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 03:48:21",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921456": [
        {
            "ioc_value": "43.138.153.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 03:48:19",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921455": [
        {
            "ioc_value": "candxai.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-17 03:47:45",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921323": [
        {
            "ioc_value": "102.220.163.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 20:05:07",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1921318": [
        {
            "ioc_value": "89.147.108.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-16 19:47:36",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921317": [
        {
            "ioc_value": "68.64.177.24:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-16 19:47:20",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921316": [
        {
            "ioc_value": "45.202.0.111:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-16 19:46:54",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921315": [
        {
            "ioc_value": "45.150.109.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-16 19:46:49",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921314": [
        {
            "ioc_value": "31.76.125.14:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:29",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921312": [
        {
            "ioc_value": "31.57.38.139:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:27",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921313": [
        {
            "ioc_value": "31.57.38.139:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:27",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921309": [
        {
            "ioc_value": "23.171.176.253:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:18",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921310": [
        {
            "ioc_value": "23.171.176.253:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:18",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921311": [
        {
            "ioc_value": "23.171.176.253:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:18",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921307": [
        {
            "ioc_value": "217.156.66.203:3607",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:09",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921308": [
        {
            "ioc_value": "217.156.66.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:46:09",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921305": [
        {
            "ioc_value": "185.212.128.32:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-16 19:44:40",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921304": [
        {
            "ioc_value": "172.94.18.103:78",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 19:44:27",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921302": [
        {
            "ioc_value": "172.86.91.14:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:44:26",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921303": [
        {
            "ioc_value": "172.86.91.14:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:44:26",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921301": [
        {
            "ioc_value": "172.86.112.104:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 19:44:24",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921300": [
        {
            "ioc_value": "154.18.238.18:8660",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-16 19:43:58",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921299": [
        {
            "ioc_value": "150.241.203.12:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:54",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921297": [
        {
            "ioc_value": "144.31.25.62:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921298": [
        {
            "ioc_value": "144.31.25.62:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921296": [
        {
            "ioc_value": "143.20.185.213:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-16 19:43:45",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921295": [
        {
            "ioc_value": "128.90.141.49:1110",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 19:43:35",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921292": [
        {
            "ioc_value": "108.187.4.123:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921293": [
        {
            "ioc_value": "108.187.4.123:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921294": [
        {
            "ioc_value": "108.187.4.123:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921291": [
        {
            "ioc_value": "104.243.248.63:3605",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 19:43:17",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921290": [
        {
            "ioc_value": "103.97.131.179:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:14",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921289": [
        {
            "ioc_value": "102.220.163.36:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:09",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921287": [
        {
            "ioc_value": "102.220.163.36:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921288": [
        {
            "ioc_value": "102.220.163.36:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921286": [
        {
            "ioc_value": "102.117.165.131:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-16 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1921276": [
        {
            "ioc_value": "102.220.163.36:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 19:05:05",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1921176": [
        {
            "ioc_value": "https://k3.zk89.net",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-09-16 16:43:51",
            "last_seen_utc": "2026-10-11 07:34:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d11f5c04051e332b9cfaabcb37c2ada9,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1921148": [
        {
            "ioc_value": "https://fide45felhs.com/work/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-09-16 15:07:01",
            "last_seen_utc": "2026-10-11 09:48:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1921082": [
        {
            "ioc_value": "103.83.86.147:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-16 11:47:10",
            "last_seen_utc": "2026-10-11 07:54:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1921039": [
        {
            "ioc_value": "www.lambayecano.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-16 09:56:42",
            "last_seen_utc": "2026-10-11 07:07:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1921006": [
        {
            "ioc_value": "flyersholding.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-16 09:56:39",
            "last_seen_utc": "2026-10-10 19:14:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1920988": [
        {
            "ioc_value": "speedpi12321.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-16 09:55:55",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "attacker-infra,ClickFix,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1920986": [
        {
            "ioc_value": "95.158.131.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-16 09:48:22",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920985": [
        {
            "ioc_value": "66.29.134.188:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-16 09:47:44",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920984": [
        {
            "ioc_value": "5.56.25.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 09:47:31",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920983": [
        {
            "ioc_value": "46.225.119.0:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-16 09:47:26",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920982": [
        {
            "ioc_value": "45.249.89.172:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-16 09:47:20",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920980": [
        {
            "ioc_value": "45.202.0.111:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-16 09:47:19",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920981": [
        {
            "ioc_value": "45.202.0.116:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-16 09:47:19",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920978": [
        {
            "ioc_value": "217.60.76.250:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:46:38",
            "last_seen_utc": "2026-10-11 09:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920979": [
        {
            "ioc_value": "217.60.76.250:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:46:38",
            "last_seen_utc": "2026-10-11 09:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920977": [
        {
            "ioc_value": "206.206.103.203:29578",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-16 09:45:44",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920976": [
        {
            "ioc_value": "172.94.18.103:74",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:44:35",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920975": [
        {
            "ioc_value": "172.86.112.104:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:44:33",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920974": [
        {
            "ioc_value": "172.86.112.104:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:44:32",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920972": [
        {
            "ioc_value": "154.36.161.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-16 09:44:06",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920971": [
        {
            "ioc_value": "144.91.78.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 09:43:53",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920970": [
        {
            "ioc_value": "139.180.153.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-16 09:43:45",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920969": [
        {
            "ioc_value": "121.200.216.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:43:33",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920968": [
        {
            "ioc_value": "102.220.163.36:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:43:09",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920967": [
        {
            "ioc_value": "102.220.160.198:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-16 09:43:07",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920841": [
        {
            "ioc_value": "156.239.224.131:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-16 06:24:42",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "984,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1920900": [
        {
            "ioc_value": "tftp2.sh",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-16 06:24:35",
            "last_seen_utc": "2026-10-11 06:11:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1920870": [
        {
            "ioc_value": "45.61.170.191:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-16 03:47:45",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920871": [
        {
            "ioc_value": "45.61.170.191:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-16 03:47:45",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920869": [
        {
            "ioc_value": "42.193.239.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-16 03:47:43",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920860": [
        {
            "ioc_value": "175.43.223.203:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-16 03:05:06",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1920633": [
        {
            "ioc_value": "sharjahtodip.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-15 20:39:52",
            "last_seen_utc": "2026-10-11 02:58:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1920626": [
        {
            "ioc_value": "positiveawards.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-15 20:39:51",
            "last_seen_utc": "2026-10-11 01:03:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1920493": [
        {
            "ioc_value": "95.158.131.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:47:26",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920494": [
        {
            "ioc_value": "95.158.131.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:47:26",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920495": [
        {
            "ioc_value": "95.158.131.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:47:26",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920490": [
        {
            "ioc_value": "94.26.81.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:47:25",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920491": [
        {
            "ioc_value": "95.158.131.135:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:47:25",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920492": [
        {
            "ioc_value": "95.158.131.139:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:47:25",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920489": [
        {
            "ioc_value": "93.152.224.238:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-15 19:47:20",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920487": [
        {
            "ioc_value": "85.137.252.195:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:47:10",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920488": [
        {
            "ioc_value": "85.239.149.73:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-15 19:47:10",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920486": [
        {
            "ioc_value": "82.26.66.136:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 19:47:07",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920485": [
        {
            "ioc_value": "82.146.37.83:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-15 19:47:05",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920483": [
        {
            "ioc_value": "80.76.49.129:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:47:04",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920484": [
        {
            "ioc_value": "80.76.49.129:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:47:04",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920482": [
        {
            "ioc_value": "77.90.14.60:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-15 19:47:00",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920481": [
        {
            "ioc_value": "67.205.148.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:46:56",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920480": [
        {
            "ioc_value": "45.202.0.116:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 19:46:34",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920477": [
        {
            "ioc_value": "31.76.125.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:46:09",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920478": [
        {
            "ioc_value": "31.76.125.3:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:46:09",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920479": [
        {
            "ioc_value": "31.76.125.3:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:46:09",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920476": [
        {
            "ioc_value": "31.57.147.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:46:05",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920475": [
        {
            "ioc_value": "213.111.149.141:3125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-15 19:45:17",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920474": [
        {
            "ioc_value": "208.84.103.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-15 19:45:14",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920473": [
        {
            "ioc_value": "195.177.94.94:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:44:56",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920471": [
        {
            "ioc_value": "195.177.94.4:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:44:55",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920472": [
        {
            "ioc_value": "195.177.94.4:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:44:55",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920470": [
        {
            "ioc_value": "193.25.215.83:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:44:49",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920469": [
        {
            "ioc_value": "121.200.216.74:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 19:43:27",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920467": [
        {
            "ioc_value": "118.107.1.203:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920468": [
        {
            "ioc_value": "118.107.1.203:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920466": [
        {
            "ioc_value": "102.220.163.36:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 19:43:07",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920465": [
        {
            "ioc_value": "102.117.167.205:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920429": [
        {
            "ioc_value": "8.146.227.247:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-15 17:05:06",
            "last_seen_utc": "2026-10-11 08:17:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1920430": [
        {
            "ioc_value": "8.146.227.247:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-15 17:05:06",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1920385": [
        {
            "ioc_value": "47.108.225.4:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-15 14:05:05",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1920378": [
        {
            "ioc_value": "130.94.29.101:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-15 13:48:28",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920355": [
        {
            "ioc_value": "23.132.164.3:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-15 13:00:57",
            "last_seen_utc": "2026-10-11 09:02:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5213e701e9eef93b8d11c54334592c272a299c057bbc73db6741fdd2dd718262/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920336": [
        {
            "ioc_value": "95.182.87.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.jackskid",
            "malware_alias": "RCtea",
            "malware_printable": "Jackskid",
            "first_seen_utc": "2026-09-15 12:24:53",
            "last_seen_utc": "2026-10-10 13:38:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/jackskid",
            "tags": "botnet,ddos,jackskid,mirai,rctea",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1920314": [
        {
            "ioc_value": "95.158.131.144:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 09:47:15",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920315": [
        {
            "ioc_value": "95.158.131.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 09:47:15",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920313": [
        {
            "ioc_value": "94.154.32.104:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 09:47:11",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920312": [
        {
            "ioc_value": "82.26.66.136:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 09:46:56",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920311": [
        {
            "ioc_value": "57.154.15.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-15 09:46:40",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920310": [
        {
            "ioc_value": "46.40.228.158:1723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 09:46:33",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920308": [
        {
            "ioc_value": "45.207.241.27:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 09:46:26",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920309": [
        {
            "ioc_value": "45.207.241.47:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 09:46:26",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920307": [
        {
            "ioc_value": "45.127.35.199:18080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-15 09:46:18",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920306": [
        {
            "ioc_value": "38.54.88.188:65432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-15 09:46:13",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920305": [
        {
            "ioc_value": "217.60.195.50:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 09:45:52",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920303": [
        {
            "ioc_value": "217.60.195.50:1313",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 09:45:51",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920304": [
        {
            "ioc_value": "217.60.195.50:1453",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 09:45:51",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920302": [
        {
            "ioc_value": "212.224.107.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 09:45:14",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920301": [
        {
            "ioc_value": "194.26.192.153:4441",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 09:44:50",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920300": [
        {
            "ioc_value": "185.249.199.108:1178",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-15 09:44:34",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920299": [
        {
            "ioc_value": "185.164.57.60:4999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-15 09:44:28",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920298": [
        {
            "ioc_value": "158.247.202.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-15 09:44:00",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920297": [
        {
            "ioc_value": "157.173.195.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-15 09:43:58",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920296": [
        {
            "ioc_value": "144.91.78.57:4810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-15 09:43:44",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920295": [
        {
            "ioc_value": "141.148.194.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-15 09:43:39",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920294": [
        {
            "ioc_value": "128.90.105.59:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-15 09:43:30",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1920293": [
        {
            "ioc_value": "109.227.48.165:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-15 09:43:24",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918315": [
        {
            "ioc_value": "13.192.33.5:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-09-15 06:04:33",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "16509,brute ratel,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1918344": [
        {
            "ioc_value": "223.109.142.7:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-15 03:47:38",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918075": [
        {
            "ioc_value": "www.robloxfruit.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:22",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918076": [
        {
            "ioc_value": "www.vieclamuytin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:22",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918077": [
        {
            "ioc_value": "zafirasasha.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:22",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918062": [
        {
            "ioc_value": "mthnomex.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918063": [
        {
            "ioc_value": "nslegends.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918065": [
        {
            "ioc_value": "plumbing215.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918066": [
        {
            "ioc_value": "prestigegaragecare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918068": [
        {
            "ioc_value": "rafaelsotto.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918069": [
        {
            "ioc_value": "ratehive.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918070": [
        {
            "ioc_value": "reeshapk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918071": [
        {
            "ioc_value": "thehempfatherus.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918073": [
        {
            "ioc_value": "vorcis.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:21",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918052": [
        {
            "ioc_value": "come-chop.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:20",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918055": [
        {
            "ioc_value": "dom-inn.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:20",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918057": [
        {
            "ioc_value": "gamoratalks.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:20",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918058": [
        {
            "ioc_value": "jennmp.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:20",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918059": [
        {
            "ioc_value": "kenmosavillage.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:20",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918060": [
        {
            "ioc_value": "kianshimisepanta.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:20",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918046": [
        {
            "ioc_value": "aihjo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:19",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918047": [
        {
            "ioc_value": "arlingtongaragedoorinc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:19",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918048": [
        {
            "ioc_value": "autocitypeninsula.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:19",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918049": [
        {
            "ioc_value": "bazarbd.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:19",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918050": [
        {
            "ioc_value": "candidlykaite.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:19",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918051": [
        {
            "ioc_value": "codiwaves.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 20:18:19",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,hardware-fingerprint",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1918028": [
        {
            "ioc_value": "littlevictories.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:59:43",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1918027": [
        {
            "ioc_value": "pagyamorim.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:59:42",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1918023": [
        {
            "ioc_value": "nigerianationalsanitationconference.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:49:22",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1918021": [
        {
            "ioc_value": "82.26.66.179:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 19:47:42",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918020": [
        {
            "ioc_value": "45.192.214.54:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-14 19:47:08",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918019": [
        {
            "ioc_value": "217.60.76.250:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 19:46:31",
            "last_seen_utc": "2026-10-11 09:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918018": [
        {
            "ioc_value": "207.89.17.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-14 19:45:42",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918017": [
        {
            "ioc_value": "198.44.167.14:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-14 19:45:31",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918016": [
        {
            "ioc_value": "188.212.158.203:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 19:45:06",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918015": [
        {
            "ioc_value": "185.212.129.79:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-14 19:44:51",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918014": [
        {
            "ioc_value": "137.220.194.12:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-14 19:43:50",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918013": [
        {
            "ioc_value": "135.136.147.238:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918012": [
        {
            "ioc_value": "118.107.1.203:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-14 19:43:37",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1918008": [
        {
            "ioc_value": "yumppad.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:39:20",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1918009": [
        {
            "ioc_value": "taxi-amsterdamservice.nl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:39:20",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1918010": [
        {
            "ioc_value": "befitacademy.com.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:39:20",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1917994": [
        {
            "ioc_value": "daraleilm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:29:15",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1917968": [
        {
            "ioc_value": "gurra-pdsh.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:19:11",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1917958": [
        {
            "ioc_value": "bgclubofnems.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 19:09:05",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1917934": [
        {
            "ioc_value": "102.220.160.198:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 18:06:48",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1917889": [
        {
            "ioc_value": "moss-froggaee.space",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:24",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917890": [
        {
            "ioc_value": "norkapi41.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:24",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917891": [
        {
            "ioc_value": "norrykilu231.digital",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:24",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917893": [
        {
            "ioc_value": "rokkyho32.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:24",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917895": [
        {
            "ioc_value": "usual-pixx12.digital",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:24",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917881": [
        {
            "ioc_value": "carwowk872.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:23",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917883": [
        {
            "ioc_value": "evrything-pix.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:23",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917887": [
        {
            "ioc_value": "gpixx.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-14 16:53:23",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,inject-domain,Mac,MacFinger",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1917781": [
        {
            "ioc_value": "180.184.46.116:10074",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-14 13:47:58",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917780": [
        {
            "ioc_value": "120.53.19.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-14 13:47:51",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917779": [
        {
            "ioc_value": "101.201.103.158:8066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-14 13:47:42",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917700": [
        {
            "ioc_value": "139.196.174.152:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-14 12:05:08",
            "last_seen_utc": "2026-10-10 09:30:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1917324": [
        {
            "ioc_value": "192.162.199.242:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-14 12:03:48",
            "last_seen_utc": "2026-10-11 05:35:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "5000,c2,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1917603": [
        {
            "ioc_value": "102.117.165.202:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 11:19:22",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/102.117.165.202#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1917599": [
        {
            "ioc_value": "31.156.181.5:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-09-14 11:18:36",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/31.156.181.5#9002",
            "tags": "bruteratel,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1917593": [
        {
            "ioc_value": "103.253.212.216:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-14 11:18:06",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/103.253.212.216#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1917537": [
        {
            "ioc_value": "151.243.126.22:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-14 11:14:00",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/151.243.126.22#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1917395": [
        {
            "ioc_value": "155.94.154.152:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-14 11:12:50",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/155.94.154.152#80",
            "tags": "c2,gophish,phishing,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1917326": [
        {
            "ioc_value": "167.17.47.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-14 11:11:39",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.17.47.252#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1917313": [
        {
            "ioc_value": "82.26.66.179:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:47:28",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917312": [
        {
            "ioc_value": "45.207.241.27:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-14 09:46:52",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917311": [
        {
            "ioc_value": "193.8.187.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-14 09:44:55",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917309": [
        {
            "ioc_value": "192.162.199.179:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:44:47",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917310": [
        {
            "ioc_value": "192.169.176.54:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-14 09:44:47",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917308": [
        {
            "ioc_value": "185.34.147.34:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917307": [
        {
            "ioc_value": "185.34.147.33:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917306": [
        {
            "ioc_value": "185.34.147.32:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:44:40",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917305": [
        {
            "ioc_value": "185.34.147.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917304": [
        {
            "ioc_value": "161.248.179.92:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:44:09",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917303": [
        {
            "ioc_value": "154.214.2.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-14 09:43:55",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917302": [
        {
            "ioc_value": "149.30.222.243:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:43:48",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917301": [
        {
            "ioc_value": "144.172.106.62:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-14 09:43:43",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917300": [
        {
            "ioc_value": "135.136.147.238:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:43:36",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917299": [
        {
            "ioc_value": "130.94.42.202:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-14 09:43:34",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917298": [
        {
            "ioc_value": "104.164.46.36:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-14 09:43:13",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917297": [
        {
            "ioc_value": "102.220.160.198:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-14 09:43:06",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917163": [
        {
            "ioc_value": "157.245.76.251:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:55",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917164": [
        {
            "ioc_value": "164.92.152.141:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:55",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917165": [
        {
            "ioc_value": "167.172.32.113:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:54",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917166": [
        {
            "ioc_value": "167.172.45.217:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:54",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917167": [
        {
            "ioc_value": "167.99.219.230:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:53",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917168": [
        {
            "ioc_value": "178.62.244.142:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:53",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917169": [
        {
            "ioc_value": "188.166.100.18:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:52",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917170": [
        {
            "ioc_value": "188.166.35.43:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:52",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917171": [
        {
            "ioc_value": "206.189.111.119:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:52",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917172": [
        {
            "ioc_value": "209.38.37.114:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:51",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917173": [
        {
            "ioc_value": "212.193.31.145:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:51",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917174": [
        {
            "ioc_value": "85.234.91.247:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:50",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917175": [
        {
            "ioc_value": "89.19.223.49:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:50",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917176": [
        {
            "ioc_value": "91.224.92.203:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-09-14 08:01:43",
            "last_seen_utc": "2026-10-10 11:06:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/kimwolf",
            "tags": "botnet,ddos,kimwolf,proxy",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1917134": [
        {
            "ioc_value": "46.151.182.237:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-14 07:25:19",
            "last_seen_utc": "2026-10-11 06:16:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9ffcc473076a03e3b8e0c839e73276c7ab71d9acdf6d4c76968472cbf7391d4f/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917118": [
        {
            "ioc_value": "172.245.209.188:2556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-14 06:10:45",
            "last_seen_utc": "2026-10-11 06:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,monipro,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1917085": [
        {
            "ioc_value": "137.220.205.193:5566",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-14 03:47:32",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1917076": [
        {
            "ioc_value": "46.151.182.6:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-14 03:05:21",
            "last_seen_utc": "2026-10-11 05:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/604495eeedb9f4124706a35b0907213716f43af17e7662e15e8c15eb41c13c46/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916965": [
        {
            "ioc_value": "104.248.156.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-13 20:05:08",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1916958": [
        {
            "ioc_value": "94.237.62.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-13 19:46:52",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916957": [
        {
            "ioc_value": "94.154.32.24:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:46:50",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916956": [
        {
            "ioc_value": "84.247.187.47:6660",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-13 19:46:38",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916955": [
        {
            "ioc_value": "66.179.29.5:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:46:26",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916954": [
        {
            "ioc_value": "45.139.104.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:58",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916952": [
        {
            "ioc_value": "38.54.13.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-13 19:45:52",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916953": [
        {
            "ioc_value": "38.54.13.48:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-13 19:45:52",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916950": [
        {
            "ioc_value": "38.180.146.89:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:51",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916951": [
        {
            "ioc_value": "38.180.146.89:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:51",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916949": [
        {
            "ioc_value": "38.180.146.89:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:50",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916948": [
        {
            "ioc_value": "34.222.23.196:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-09-13 19:45:46",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916947": [
        {
            "ioc_value": "31.56.209.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:41",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916945": [
        {
            "ioc_value": "217.60.195.25:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916946": [
        {
            "ioc_value": "217.60.77.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916943": [
        {
            "ioc_value": "217.60.195.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:32",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916944": [
        {
            "ioc_value": "217.60.195.25:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:32",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916941": [
        {
            "ioc_value": "217.60.195.160:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:31",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916942": [
        {
            "ioc_value": "217.60.195.160:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:31",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916940": [
        {
            "ioc_value": "217.217.97.65:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:45:29",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916938": [
        {
            "ioc_value": "195.177.94.23:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916939": [
        {
            "ioc_value": "195.177.94.23:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916937": [
        {
            "ioc_value": "192.162.199.179:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-13 19:44:31",
            "last_seen_utc": "2026-10-11 09:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916936": [
        {
            "ioc_value": "155.2.192.251:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:43:50",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916934": [
        {
            "ioc_value": "153.56.180.134:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:43:45",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916935": [
        {
            "ioc_value": "153.56.180.134:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 19:43:45",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916933": [
        {
            "ioc_value": "102.117.168.128:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-13 19:43:05",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916628": [
        {
            "ioc_value": "183.60.226.2:38080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 13:47:06",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916626": [
        {
            "ioc_value": "137.220.205.181:5566",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 13:46:59",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916627": [
        {
            "ioc_value": "137.220.205.196:5566",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 13:46:59",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916625": [
        {
            "ioc_value": "121.43.152.104:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 13:46:58",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916415": [
        {
            "ioc_value": "9dgamelogin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-13 12:10:13",
            "last_seen_utc": "2026-10-09 22:17:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1916414": [
        {
            "ioc_value": "workworm1412.buzz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-13 12:09:12",
            "last_seen_utc": "2026-10-10 22:28:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,Mac,MacFinger,payload-infra",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1916263": [
        {
            "ioc_value": "130.12.181.199:10213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.cecbot",
            "malware_alias": null,
            "malware_printable": "CECbot",
            "first_seen_utc": "2026-09-13 11:45:55",
            "last_seen_utc": "2026-10-10 13:19:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/tree/main/cecbot",
            "tags": "android,botnet,cecbot,ddos",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1916185": [
        {
            "ioc_value": "93.82.31.87:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-09-13 09:47:33",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916184": [
        {
            "ioc_value": "84.247.187.47:4546",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-13 09:47:19",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916183": [
        {
            "ioc_value": "45.139.104.26:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 09:46:36",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916182": [
        {
            "ioc_value": "38.180.146.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 09:46:29",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916181": [
        {
            "ioc_value": "31.56.209.63:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 09:46:17",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916180": [
        {
            "ioc_value": "196.251.121.238:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-13 09:45:13",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916179": [
        {
            "ioc_value": "192.238.177.18:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-13 09:44:54",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916177": [
        {
            "ioc_value": "192.238.177.14:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-13 09:44:53",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916178": [
        {
            "ioc_value": "192.238.177.14:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-13 09:44:53",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916176": [
        {
            "ioc_value": "167.233.243.9:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-13 09:44:14",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916175": [
        {
            "ioc_value": "162.35.107.168:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-13 09:44:11",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916173": [
        {
            "ioc_value": "160.191.88.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-13 09:44:09",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916174": [
        {
            "ioc_value": "160.191.88.70:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-13 09:44:09",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916172": [
        {
            "ioc_value": "144.172.106.62:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-13 09:43:43",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916171": [
        {
            "ioc_value": "128.90.112.54:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-13 09:43:32",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916170": [
        {
            "ioc_value": "102.220.160.198:1505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-13 09:43:05",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916053": [
        {
            "ioc_value": "156.254.20.46:5996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 06:33:54",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "400619,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1916054": [
        {
            "ioc_value": "156.254.20.46:5998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 06:33:54",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "400619,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1916119": [
        {
            "ioc_value": "49.233.202.218:7878",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 04:49:06",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916120": [
        {
            "ioc_value": "5.104.86.108:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-13 04:49:06",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1916115": [
        {
            "ioc_value": "148.66.17.125:60003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-09-13 04:05:07",
            "last_seen_utc": "2026-10-11 02:49:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1916091": [
        {
            "ioc_value": "120.26.120.83:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-09-13 03:05:05",
            "last_seen_utc": "2026-10-10 00:15:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1915978": [
        {
            "ioc_value": "47.118.26.230:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-09-12 20:05:05",
            "last_seen_utc": "2026-10-10 00:20:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1915968": [
        {
            "ioc_value": "52.141.89.123:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 19:46:40",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915967": [
        {
            "ioc_value": "45.192.226.20:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:46:28",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915965": [
        {
            "ioc_value": "45.192.169.57:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 19:46:25",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915966": [
        {
            "ioc_value": "45.192.169.58:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 19:46:25",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915964": [
        {
            "ioc_value": "45.192.169.186:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 19:46:24",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915963": [
        {
            "ioc_value": "31.57.51.110:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 19:46:05",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915962": [
        {
            "ioc_value": "31.56.209.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:46:03",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915961": [
        {
            "ioc_value": "23.226.57.95:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 19:45:56",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915959": [
        {
            "ioc_value": "213.209.159.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:45:18",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915957": [
        {
            "ioc_value": "194.9.6.125:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:44:50",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915958": [
        {
            "ioc_value": "194.9.6.125:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:44:50",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915955": [
        {
            "ioc_value": "193.25.215.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:44:46",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915956": [
        {
            "ioc_value": "193.25.215.37:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:44:46",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915954": [
        {
            "ioc_value": "192.238.177.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 19:44:43",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915953": [
        {
            "ioc_value": "192.177.26.195:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:44:40",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915951": [
        {
            "ioc_value": "151.242.63.126:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915950": [
        {
            "ioc_value": "141.98.11.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915949": [
        {
            "ioc_value": "102.117.165.85:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915671": [
        {
            "ioc_value": "49.51.230.17:53001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 13:48:33",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915670": [
        {
            "ioc_value": "38.76.183.197:8806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 13:48:26",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915669": [
        {
            "ioc_value": "165.154.68.30:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 13:48:18",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915617": [
        {
            "ioc_value": "94.26.248.76:50050",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-12 09:47:52",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915616": [
        {
            "ioc_value": "84.247.141.236:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-12 09:47:36",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915613": [
        {
            "ioc_value": "66.94.113.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 09:47:25",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915614": [
        {
            "ioc_value": "68.178.202.150:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-12 09:47:25",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915615": [
        {
            "ioc_value": "68.178.205.17:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-12 09:47:25",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915612": [
        {
            "ioc_value": "65.108.13.44:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 09:47:23",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915611": [
        {
            "ioc_value": "46.246.4.10:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 09:47:08",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915610": [
        {
            "ioc_value": "37.244.232.113:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-12 09:46:41",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915609": [
        {
            "ioc_value": "208.167.253.21:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 09:45:36",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915608": [
        {
            "ioc_value": "194.110.172.193:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 09:45:12",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915607": [
        {
            "ioc_value": "187.145.61.38:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 09:44:55",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915606": [
        {
            "ioc_value": "166.1.249.50:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-12 09:44:19",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915605": [
        {
            "ioc_value": "13.251.42.119:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-12 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915604": [
        {
            "ioc_value": "128.90.105.161:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-12 09:43:34",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915603": [
        {
            "ioc_value": "107.172.232.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-12 09:43:22",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915602": [
        {
            "ioc_value": "102.220.160.198:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-12 09:43:06",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915577": [
        {
            "ioc_value": "31.70.103.174:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 07:55:31",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915526": [
        {
            "ioc_value": "23.227.196.108:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 03:47:34",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915525": [
        {
            "ioc_value": "162.35.122.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 03:47:27",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915524": [
        {
            "ioc_value": "139.199.160.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 03:47:24",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1915523": [
        {
            "ioc_value": "networkness.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-12 03:47:11",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1913004": [
        {
            "ioc_value": "cybereye.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-09-11 23:29:40",
            "last_seen_utc": "2026-10-09 17:11:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "compromised,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1912952": [
        {
            "ioc_value": "cybercoinslab.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-11 22:57:31",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1912782": [
        {
            "ioc_value": "84.247.187.47:8818",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-11 19:47:26",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912781": [
        {
            "ioc_value": "5.175.222.230:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-11 19:46:57",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912779": [
        {
            "ioc_value": "217.60.195.40:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912780": [
        {
            "ioc_value": "217.60.195.40:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912778": [
        {
            "ioc_value": "217.217.97.90:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:46:08",
            "last_seen_utc": "2026-10-11 09:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912777": [
        {
            "ioc_value": "204.0.56.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-11 19:45:27",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912776": [
        {
            "ioc_value": "198.13.158.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-11 19:45:16",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912775": [
        {
            "ioc_value": "196.251.121.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:45:15",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912773": [
        {
            "ioc_value": "195.177.94.100:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:45:09",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912774": [
        {
            "ioc_value": "195.177.94.100:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:45:09",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912772": [
        {
            "ioc_value": "195.177.94.100:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:45:08",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912771": [
        {
            "ioc_value": "194.32.142.225:22222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-11 19:45:01",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912770": [
        {
            "ioc_value": "192.252.187.56:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:44:56",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912769": [
        {
            "ioc_value": "191.93.113.119:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-11 19:44:52",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912768": [
        {
            "ioc_value": "172.111.198.212:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:44:20",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912767": [
        {
            "ioc_value": "158.94.209.209:3009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-11 19:44:09",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912766": [
        {
            "ioc_value": "144.31.6.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912764": [
        {
            "ioc_value": "118.107.16.32:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 19:43:29",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912763": [
        {
            "ioc_value": "105.101.131.181:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-11 19:43:19",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912762": [
        {
            "ioc_value": "102.117.163.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-11 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912261": [
        {
            "ioc_value": "193.112.95.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-11 13:51:07",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912255": [
        {
            "ioc_value": "191.93.113.119:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-11 13:38:17",
            "last_seen_utc": "2026-10-10 13:56:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,PASA,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1912194": [
        {
            "ioc_value": "1309673150-86ymvxmhrm.ap-shanghai.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-11 09:47:44",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912193": [
        {
            "ioc_value": "93.82.26.11:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-09-11 09:47:38",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912192": [
        {
            "ioc_value": "92.223.85.43:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-11 09:47:36",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912190": [
        {
            "ioc_value": "88.223.43.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-11 09:47:29",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912191": [
        {
            "ioc_value": "89.124.108.211:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-11 09:47:29",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912189": [
        {
            "ioc_value": "88.223.43.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-11 09:47:28",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912188": [
        {
            "ioc_value": "84.247.187.47:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-11 09:47:25",
            "last_seen_utc": "2026-10-11 08:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912187": [
        {
            "ioc_value": "78.17.93.96:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-11 09:47:18",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912186": [
        {
            "ioc_value": "69.10.49.136:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-11 09:47:15",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912185": [
        {
            "ioc_value": "61.158.61.184:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-11 09:47:08",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912182": [
        {
            "ioc_value": "45.202.0.24:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-11 09:46:49",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912183": [
        {
            "ioc_value": "45.202.0.25:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-11 09:46:49",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912184": [
        {
            "ioc_value": "45.202.0.25:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-11 09:46:49",
            "last_seen_utc": "2026-10-11 09:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912181": [
        {
            "ioc_value": "45.145.171.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-09-11 09:46:43",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912180": [
        {
            "ioc_value": "45.13.239.249:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-11 09:46:41",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912179": [
        {
            "ioc_value": "223.130.11.38:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-11 09:46:14",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912176": [
        {
            "ioc_value": "198.199.82.231:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-11 09:45:14",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912174": [
        {
            "ioc_value": "193.111.77.180:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-11 09:44:54",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912175": [
        {
            "ioc_value": "193.111.77.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-11 09:44:54",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912173": [
        {
            "ioc_value": "162.35.100.184:1104",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-11 09:44:09",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912172": [
        {
            "ioc_value": "162.141.69.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-11 09:44:08",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912171": [
        {
            "ioc_value": "16.5.7.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-11 09:44:06",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912170": [
        {
            "ioc_value": "154.205.175.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-11 09:43:55",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912169": [
        {
            "ioc_value": "144.126.218.78:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-11 09:43:44",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912168": [
        {
            "ioc_value": "104.248.156.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-11 09:43:16",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1912146": [
        {
            "ioc_value": "47.109.23.77:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-11 08:05:06",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1911853": [
        {
            "ioc_value": "45.144.136.97:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-11 03:48:17",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911852": [
        {
            "ioc_value": "114.132.180.69:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-11 03:47:54",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911851": [
        {
            "ioc_value": "111.228.5.127:5435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-11 03:47:53",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911432": [
        {
            "ioc_value": "72.14.136.90:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:47:09",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911431": [
        {
            "ioc_value": "45.192.211.126:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:46:40",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911430": [
        {
            "ioc_value": "195.177.94.98:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:45:02",
            "last_seen_utc": "2026-10-11 08:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911429": [
        {
            "ioc_value": "193.168.175.69:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:44:53",
            "last_seen_utc": "2026-10-11 08:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911428": [
        {
            "ioc_value": "185.174.102.5:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:44:34",
            "last_seen_utc": "2026-10-11 08:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911427": [
        {
            "ioc_value": "163.5.210.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:44:10",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911426": [
        {
            "ioc_value": "153.56.180.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:43:53",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911423": [
        {
            "ioc_value": "104.249.10.118:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:43:17",
            "last_seen_utc": "2026-10-11 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911424": [
        {
            "ioc_value": "104.249.10.118:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:43:17",
            "last_seen_utc": "2026-10-11 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1911425": [
        {
            "ioc_value": "104.249.10.118:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 21:43:17",
            "last_seen_utc": "2026-10-11 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910838": [
        {
            "ioc_value": "84.247.187.47:6661",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 19:47:26",
            "last_seen_utc": "2026-10-10 18:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910839": [
        {
            "ioc_value": "84.247.187.47:8115",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 19:47:26",
            "last_seen_utc": "2026-10-10 18:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910837": [
        {
            "ioc_value": "62.171.148.175:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 19:47:06",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910836": [
        {
            "ioc_value": "45.202.0.24:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-10 19:46:48",
            "last_seen_utc": "2026-10-11 08:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910835": [
        {
            "ioc_value": "31.56.209.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-09-10 19:46:20",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910834": [
        {
            "ioc_value": "193.233.131.97:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-10 19:44:56",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910833": [
        {
            "ioc_value": "158.158.17.236:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 19:44:04",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910832": [
        {
            "ioc_value": "154.46.30.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-10 19:43:58",
            "last_seen_utc": "2026-10-11 08:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910831": [
        {
            "ioc_value": "146.70.87.218:42445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910830": [
        {
            "ioc_value": "129.153.57.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-10 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910829": [
        {
            "ioc_value": "128.90.167.181:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 19:43:33",
            "last_seen_utc": "2026-10-11 08:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910828": [
        {
            "ioc_value": "128.90.105.231:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-10 19:43:32",
            "last_seen_utc": "2026-10-11 08:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910827": [
        {
            "ioc_value": "102.220.160.198:3500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 19:43:06",
            "last_seen_utc": "2026-10-10 18:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910826": [
        {
            "ioc_value": "102.117.168.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-10 19:43:05",
            "last_seen_utc": "2026-10-11 08:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1910791": [
        {
            "ioc_value": "sobrevela.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-10 18:35:50",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1910665": [
        {
            "ioc_value": "pacifictec.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-10 17:24:14",
            "last_seen_utc": "2026-10-11 01:13:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1910652": [
        {
            "ioc_value": "marcela-beran.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-10 17:24:13",
            "last_seen_utc": "2026-10-09 17:11:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1907181": [
        {
            "ioc_value": "38.76.190.209:8090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-10 13:48:51",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907179": [
        {
            "ioc_value": "209.200.246.80:26513",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-10 13:48:48",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907180": [
        {
            "ioc_value": "209.200.246.80:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-10 13:48:48",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907156": [
        {
            "ioc_value": "216.9.225.150:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-10 13:24:15",
            "last_seen_utc": "2026-10-11 07:13:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1907083": [
        {
            "ioc_value": "193.160.223.238:31896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-10 11:08:00",
            "last_seen_utc": "2026-10-09 10:27:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,FAKE,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1907070": [
        {
            "ioc_value": "98.89.43.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 09:47:49",
            "last_seen_utc": "2026-10-10 20:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907068": [
        {
            "ioc_value": "95.31.213.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-10 09:47:48",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907069": [
        {
            "ioc_value": "96.9.226.22:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:47:48",
            "last_seen_utc": "2026-10-10 18:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907067": [
        {
            "ioc_value": "80.96.108.225:65432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 09:47:25",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907066": [
        {
            "ioc_value": "80.190.77.86:2002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:47:23",
            "last_seen_utc": "2026-10-10 08:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907065": [
        {
            "ioc_value": "69.48.229.91:65500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 09:47:19",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907063": [
        {
            "ioc_value": "62.171.148.175:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:47:12",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907064": [
        {
            "ioc_value": "62.171.148.175:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:47:12",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907061": [
        {
            "ioc_value": "38.54.97.169:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 09:46:39",
            "last_seen_utc": "2026-10-10 18:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907060": [
        {
            "ioc_value": "206.123.132.166:3002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-10 09:45:29",
            "last_seen_utc": "2026-10-10 18:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907059": [
        {
            "ioc_value": "195.2.80.76:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-10 09:45:16",
            "last_seen_utc": "2026-10-10 18:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907058": [
        {
            "ioc_value": "194.26.192.153:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:45:07",
            "last_seen_utc": "2026-10-10 18:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907057": [
        {
            "ioc_value": "185.242.3.250:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:44:46",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907056": [
        {
            "ioc_value": "185.212.128.237:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-10 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907055": [
        {
            "ioc_value": "184.176.151.16:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-09-10 09:44:38",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907054": [
        {
            "ioc_value": "18.142.104.108:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-10 09:44:34",
            "last_seen_utc": "2026-10-10 18:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907052": [
        {
            "ioc_value": "172.86.74.104:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:44:27",
            "last_seen_utc": "2026-10-10 18:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907053": [
        {
            "ioc_value": "172.86.74.104:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:44:27",
            "last_seen_utc": "2026-10-10 18:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907051": [
        {
            "ioc_value": "154.13.7.196:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 09:43:58",
            "last_seen_utc": "2026-10-10 18:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907050": [
        {
            "ioc_value": "144.172.65.54:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 09:43:48",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907049": [
        {
            "ioc_value": "143.246.217.103:25729",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-10 09:43:46",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907048": [
        {
            "ioc_value": "138.16.178.77:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:43:43",
            "last_seen_utc": "2026-10-10 18:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907046": [
        {
            "ioc_value": "128.90.135.53:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:43:34",
            "last_seen_utc": "2026-10-10 18:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907045": [
        {
            "ioc_value": "124.156.108.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 09:43:32",
            "last_seen_utc": "2026-10-10 20:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907044": [
        {
            "ioc_value": "107.172.134.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-10 09:43:21",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1907043": [
        {
            "ioc_value": "103.108.66.160:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 09:43:08",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906811": [
        {
            "ioc_value": "111.228.49.20:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-10 05:13:50",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1906864": [
        {
            "ioc_value": "38.190.198.56:23251",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-10 03:48:54",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906837": [
        {
            "ioc_value": "102.220.161.94:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-10 02:40:03",
            "last_seen_utc": "2026-10-11 08:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906424": [
        {
            "ioc_value": "96.9.226.22:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:47:44",
            "last_seen_utc": "2026-10-10 08:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906422": [
        {
            "ioc_value": "84.247.187.47:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:47:25",
            "last_seen_utc": "2026-10-10 08:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906423": [
        {
            "ioc_value": "84.247.187.47:9918",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:47:25",
            "last_seen_utc": "2026-10-10 08:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906421": [
        {
            "ioc_value": "82.22.7.20:50604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:47:23",
            "last_seen_utc": "2026-10-10 08:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906420": [
        {
            "ioc_value": "79.76.35.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-09-09 19:47:17",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906419": [
        {
            "ioc_value": "65.87.7.11:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 19:47:12",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906418": [
        {
            "ioc_value": "38.247.165.127:9990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:46:33",
            "last_seen_utc": "2026-10-10 08:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906417": [
        {
            "ioc_value": "31.76.103.200:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:46:24",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906416": [
        {
            "ioc_value": "217.60.195.139:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:46:09",
            "last_seen_utc": "2026-10-10 08:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906415": [
        {
            "ioc_value": "212.43.153.205:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:45:32",
            "last_seen_utc": "2026-10-10 08:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906414": [
        {
            "ioc_value": "202.162.99.199:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:45:24",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906413": [
        {
            "ioc_value": "192.241.151.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-09 19:44:56",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906412": [
        {
            "ioc_value": "187.145.125.245:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 19:44:50",
            "last_seen_utc": "2026-10-10 08:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906410": [
        {
            "ioc_value": "186.240.202.85:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:44:49",
            "last_seen_utc": "2026-10-11 08:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906411": [
        {
            "ioc_value": "186.240.202.89:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:44:49",
            "last_seen_utc": "2026-10-11 08:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906409": [
        {
            "ioc_value": "172.234.71.84:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 19:44:21",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906408": [
        {
            "ioc_value": "150.40.98.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 19:43:54",
            "last_seen_utc": "2026-10-10 08:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906407": [
        {
            "ioc_value": "146.70.79.45:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-09 19:43:50",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906406": [
        {
            "ioc_value": "144.172.112.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:43:47",
            "last_seen_utc": "2026-10-10 08:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906404": [
        {
            "ioc_value": "137.220.194.12:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:43:43",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906405": [
        {
            "ioc_value": "138.16.178.77:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:43:43",
            "last_seen_utc": "2026-10-10 08:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906403": [
        {
            "ioc_value": "137.220.194.12:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906402": [
        {
            "ioc_value": "118.107.16.32:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906401": [
        {
            "ioc_value": "107.172.134.37:6677",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 19:43:22",
            "last_seen_utc": "2026-10-10 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906400": [
        {
            "ioc_value": "103.108.66.160:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 19:43:09",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906399": [
        {
            "ioc_value": "102.117.161.77:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 19:43:05",
            "last_seen_utc": "2026-10-10 08:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906353": [
        {
            "ioc_value": "15.235.204.60:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 18:05:05",
            "last_seen_utc": "2026-10-10 08:43:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1906290": [
        {
            "ioc_value": "31.13.190.58:9559",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-09 15:40:01",
            "last_seen_utc": "2026-10-11 07:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Yakuze Crypter Sep 2026",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1906273": [
        {
            "ioc_value": "31.13.190.58:32635",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-09 15:26:29",
            "last_seen_utc": "2026-10-11 07:36:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Yakuze Crypter Sep 2026",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1906279": [
        {
            "ioc_value": "93.127.160.86:9559",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-09 15:26:28",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Yakuze Crypter Sep 2026",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1906271": [
        {
            "ioc_value": "31.13.190.58:9441",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-09 15:18:19",
            "last_seen_utc": "2026-10-11 08:02:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Yakuze Crypter Sep 2026",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1906269": [
        {
            "ioc_value": "31.13.190.58:9442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-09 15:18:18",
            "last_seen_utc": "2026-10-11 07:29:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,Yakuze Crypter Sep 2026",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1906134": [
        {
            "ioc_value": "152.136.253.101:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-09 12:05:05",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1906076": [
        {
            "ioc_value": "46.246.84.8:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-09 09:47:20",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906077": [
        {
            "ioc_value": "46.246.84.8:6490",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-09 09:47:20",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906075": [
        {
            "ioc_value": "43.198.116.85:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:46:58",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906074": [
        {
            "ioc_value": "43.143.57.45:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:46:57",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906073": [
        {
            "ioc_value": "34.73.4.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-09 09:46:47",
            "last_seen_utc": "2026-10-09 18:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906072": [
        {
            "ioc_value": "3.6.16.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-09 09:46:38",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906070": [
        {
            "ioc_value": "23.94.206.113:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-09 09:46:34",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906071": [
        {
            "ioc_value": "23.94.206.113:50014",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-09 09:46:34",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906069": [
        {
            "ioc_value": "182.92.227.226:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:44:36",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906068": [
        {
            "ioc_value": "181.206.158.19:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-09 09:44:35",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906067": [
        {
            "ioc_value": "171.113.115.5:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:44:19",
            "last_seen_utc": "2026-10-09 18:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906066": [
        {
            "ioc_value": "154.37.218.235:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:44:00",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906065": [
        {
            "ioc_value": "153.142.13.183:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:43:56",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1906064": [
        {
            "ioc_value": "144.172.118.114:51956",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-09 09:43:48",
            "last_seen_utc": "2026-10-09 18:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905789": [
        {
            "ioc_value": "42.193.123.90:16631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-09 03:47:41",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905788": [
        {
            "ioc_value": "113.250.188.15:6784",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-09 03:47:24",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905627": [
        {
            "ioc_value": "91.92.243.114:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:47:42",
            "last_seen_utc": "2026-10-11 09:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905625": [
        {
            "ioc_value": "91.92.243.114:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:47:41",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905626": [
        {
            "ioc_value": "91.92.243.114:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:47:41",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905618": [
        {
            "ioc_value": "45.192.214.55:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:54",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905619": [
        {
            "ioc_value": "45.192.226.20:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:54",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905620": [
        {
            "ioc_value": "45.192.226.20:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:54",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905614": [
        {
            "ioc_value": "45.192.214.54:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:53",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905615": [
        {
            "ioc_value": "45.192.214.54:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:53",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905616": [
        {
            "ioc_value": "45.192.214.55:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:53",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905617": [
        {
            "ioc_value": "45.192.214.55:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:53",
            "last_seen_utc": "2026-10-11 09:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905612": [
        {
            "ioc_value": "45.192.211.116:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:51",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905613": [
        {
            "ioc_value": "45.192.211.116:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:51",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905611": [
        {
            "ioc_value": "37.72.168.163:42554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-08 19:46:36",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905609": [
        {
            "ioc_value": "23.171.177.13:7222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:46:20",
            "last_seen_utc": "2026-10-10 08:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905607": [
        {
            "ioc_value": "202.162.99.199:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:45:26",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905606": [
        {
            "ioc_value": "2.56.222.17:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-08 19:45:21",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905601": [
        {
            "ioc_value": "186.240.202.85:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:44:48",
            "last_seen_utc": "2026-10-10 08:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905602": [
        {
            "ioc_value": "186.240.202.89:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:44:48",
            "last_seen_utc": "2026-10-11 08:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905598": [
        {
            "ioc_value": "170.64.183.242:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-08 19:44:16",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905595": [
        {
            "ioc_value": "147.124.214.219:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905594": [
        {
            "ioc_value": "147.124.214.219:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:43:47",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905591": [
        {
            "ioc_value": "107.150.72.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-08 19:43:19",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905437": [
        {
            "ioc_value": "82.115.16.4:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-08 09:47:11",
            "last_seen_utc": "2026-10-10 08:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905434": [
        {
            "ioc_value": "50.60.157.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-08 09:46:50",
            "last_seen_utc": "2026-10-10 18:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905433": [
        {
            "ioc_value": "5.175.188.199:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-08 09:46:49",
            "last_seen_utc": "2026-10-11 09:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905432": [
        {
            "ioc_value": "45.142.30.100:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-08 09:46:31",
            "last_seen_utc": "2026-10-10 08:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905431": [
        {
            "ioc_value": "34.134.117.89:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-08 09:46:17",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905430": [
        {
            "ioc_value": "31.77.161.250:5667",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-08 09:46:16",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905428": [
        {
            "ioc_value": "220.154.128.196:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-08 09:46:03",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905429": [
        {
            "ioc_value": "220.154.128.196:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-08 09:46:03",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905427": [
        {
            "ioc_value": "217.60.198.81:7744",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-08 09:46:00",
            "last_seen_utc": "2026-10-11 09:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905425": [
        {
            "ioc_value": "193.233.49.79:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-08 09:44:51",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905426": [
        {
            "ioc_value": "193.239.237.120:50091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-08 09:44:51",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1905424": [
        {
            "ioc_value": "175.43.223.201:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-08 09:44:21",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1904072": [
        {
            "ioc_value": "42.194.241.92:8181",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-08 05:04:48",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1904111": [
        {
            "ioc_value": "175.178.224.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-08 03:47:24",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1904110": [
        {
            "ioc_value": "106.52.127.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-08 03:47:11",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903924": [
        {
            "ioc_value": "atxad.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-07 20:21:14",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1903910": [
        {
            "ioc_value": "209.200.246.194:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-07 19:47:48",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903908": [
        {
            "ioc_value": "cs2.acsdomaindsadas.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-07 19:47:24",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903904": [
        {
            "ioc_value": "80.190.77.86:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-07 19:46:58",
            "last_seen_utc": "2026-10-09 18:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903903": [
        {
            "ioc_value": "45.192.211.116:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:46:30",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903902": [
        {
            "ioc_value": "43.135.26.173:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:46:22",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903901": [
        {
            "ioc_value": "37.120.222.88:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:46:15",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903900": [
        {
            "ioc_value": "37.120.222.88:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:46:14",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903899": [
        {
            "ioc_value": "31.70.81.171:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-07 19:46:09",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903898": [
        {
            "ioc_value": "31.57.38.195:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:46:08",
            "last_seen_utc": "2026-10-09 18:44:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903895": [
        {
            "ioc_value": "206.238.123.77:60443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-07 19:45:08",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903894": [
        {
            "ioc_value": "20.118.221.53:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-07 19:45:00",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903893": [
        {
            "ioc_value": "194.9.6.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:44:49",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903891": [
        {
            "ioc_value": "172.111.201.220:3020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-07 19:44:09",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903888": [
        {
            "ioc_value": "159.194.232.217:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-07 19:43:57",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903887": [
        {
            "ioc_value": "107.149.8.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-07 19:43:18",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903886": [
        {
            "ioc_value": "102.220.160.198:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-07 19:43:06",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903726": [
        {
            "ioc_value": "45.195.8.27:43001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-07 13:48:28",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903569": [
        {
            "ioc_value": "23.148.212.254:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-07 09:46:04",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903568": [
        {
            "ioc_value": "213.209.159.36:1879",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-07 09:45:23",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903567": [
        {
            "ioc_value": "192.253.226.10:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-07 09:44:49",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903566": [
        {
            "ioc_value": "185.242.3.250:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-07 09:44:36",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903390": [
        {
            "ioc_value": "206.123.137.132:56090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-07 06:15:22",
            "last_seen_utc": "2026-10-11 09:41:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,septguops",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1903145": [
        {
            "ioc_value": "https://aplihartom.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-09-07 05:44:33",
            "last_seen_utc": "2026-10-11 09:31:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1903236": [
        {
            "ioc_value": "https://agrygamger.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-09-07 05:44:20",
            "last_seen_utc": "2026-10-11 09:36:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1903331": [
        {
            "ioc_value": "gloriousfuturered.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-07 04:51:53",
            "last_seen_utc": "2026-10-10 20:05:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1903318": [
        {
            "ioc_value": "bibliacientifica.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-07 04:51:49",
            "last_seen_utc": "2026-10-09 17:11:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1903281": [
        {
            "ioc_value": "ms2designstudio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-09-07 04:50:59",
            "last_seen_utc": "2026-10-11 00:12:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1903050": [
        {
            "ioc_value": "91.219.239.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:46:56",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903049": [
        {
            "ioc_value": "45.139.104.226:49001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:46:19",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903047": [
        {
            "ioc_value": "31.57.38.7:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:46:04",
            "last_seen_utc": "2026-10-11 08:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903046": [
        {
            "ioc_value": "202.162.99.199:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:45:12",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903042": [
        {
            "ioc_value": "185.242.3.250:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-06 19:44:27",
            "last_seen_utc": "2026-10-11 08:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903041": [
        {
            "ioc_value": "185.227.83.169:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:44:26",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903037": [
        {
            "ioc_value": "180.93.115.26:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-09-06 19:44:18",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903036": [
        {
            "ioc_value": "179.43.169.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-06 19:44:17",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903033": [
        {
            "ioc_value": "118.107.16.32:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903028": [
        {
            "ioc_value": "103.45.66.107:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903029": [
        {
            "ioc_value": "103.45.66.107:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1903030": [
        {
            "ioc_value": "103.45.66.107:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902203": [
        {
            "ioc_value": "192.9.157.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-06 13:47:16",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902183": [
        {
            "ioc_value": "141.98.10.154:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-06 13:17:30",
            "last_seen_utc": "2026-10-11 03:12:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,MicrosoftOutlook,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1902149": [
        {
            "ioc_value": "91.92.241.187:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-06 09:47:09",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902148": [
        {
            "ioc_value": "91.92.241.184:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-06 09:47:08",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902146": [
        {
            "ioc_value": "80.190.77.86:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-06 09:46:55",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902143": [
        {
            "ioc_value": "191.252.184.198:1080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-06 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902142": [
        {
            "ioc_value": "185.227.152.231:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-06 09:44:31",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902139": [
        {
            "ioc_value": "108.187.43.137:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 09:43:21",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902140": [
        {
            "ioc_value": "108.187.43.144:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 09:43:21",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902141": [
        {
            "ioc_value": "109.123.245.205:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-06 09:43:21",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902138": [
        {
            "ioc_value": "103.79.76.207:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-06 09:43:10",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1902112": [
        {
            "ioc_value": "156.247.62.115:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-06 08:20:29",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "DarkCrystal RAT,DCRat",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1902049": [
        {
            "ioc_value": "156.240.108.46:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 07:54:15",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1902050": [
        {
            "ioc_value": "156.240.108.46:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 07:54:14",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1902051": [
        {
            "ioc_value": "156.240.108.46:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 07:54:13",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1902052": [
        {
            "ioc_value": "179.236.107.22:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 07:54:13",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1902056": [
        {
            "ioc_value": "179.236.107.40:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 07:54:10",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1902057": [
        {
            "ioc_value": "179.236.107.40:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-06 07:54:10",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1901878": [
        {
            "ioc_value": "https://ichamier.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-09-06 06:19:54",
            "last_seen_utc": "2026-10-11 09:20:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,chma,loader,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1901906": [
        {
            "ioc_value": "51.195.113.99:3267",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-09-06 06:19:52",
            "last_seen_utc": "2026-10-09 13:44:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "945c9f3c8cddcb7f33efce50a9a949ad,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1901535": [
        {
            "ioc_value": "94.154.32.101:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-09-05 19:46:57",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901534": [
        {
            "ioc_value": "83.136.211.230:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-05 19:46:44",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901533": [
        {
            "ioc_value": "45.81.115.197:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-05 19:46:18",
            "last_seen_utc": "2026-10-11 09:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901531": [
        {
            "ioc_value": "45.139.104.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-05 19:46:10",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901529": [
        {
            "ioc_value": "45.11.230.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-05 19:46:09",
            "last_seen_utc": "2026-10-09 18:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901530": [
        {
            "ioc_value": "45.11.230.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-05 19:46:09",
            "last_seen_utc": "2026-10-10 20:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901528": [
        {
            "ioc_value": "31.70.81.171:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-05 19:45:55",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901527": [
        {
            "ioc_value": "31.59.118.107:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-05 19:45:54",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901525": [
        {
            "ioc_value": "195.66.213.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-09-05 19:44:46",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901524": [
        {
            "ioc_value": "185.212.128.233:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-05 19:44:23",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901517": [
        {
            "ioc_value": "102.220.160.198:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-05 19:43:05",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901367": [
        {
            "ioc_value": "209.200.246.194:45126",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-05 13:48:00",
            "last_seen_utc": "2026-10-10 10:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901366": [
        {
            "ioc_value": "154.197.141.252:12443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-05 13:47:53",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901365": [
        {
            "ioc_value": "154.197.141.246:12443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-05 13:47:52",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901364": [
        {
            "ioc_value": "111.230.185.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-05 13:47:44",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901363": [
        {
            "ioc_value": "103.212.186.85:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-05 13:47:41",
            "last_seen_utc": "2026-10-09 14:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901247": [
        {
            "ioc_value": "37.120.222.88:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-05 11:35:04",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1901286": [
        {
            "ioc_value": "82.23.246.148:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-05 09:47:20",
            "last_seen_utc": "2026-10-10 18:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901284": [
        {
            "ioc_value": "47.239.61.167:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-05 09:46:55",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901279": [
        {
            "ioc_value": "203.88.118.26:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-05 09:45:24",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901276": [
        {
            "ioc_value": "185.233.164.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-05 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901273": [
        {
            "ioc_value": "149.56.12.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-05 09:43:49",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1901272": [
        {
            "ioc_value": "137.175.107.110:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-05 09:43:39",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894479": [
        {
            "ioc_value": "188.227.14.105:541",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-04 19:47:51",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894475": [
        {
            "ioc_value": "82.23.246.148:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-04 19:47:07",
            "last_seen_utc": "2026-10-10 18:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894474": [
        {
            "ioc_value": "80.97.160.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-04 19:47:05",
            "last_seen_utc": "2026-10-10 08:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894472": [
        {
            "ioc_value": "38.247.165.127:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-04 19:46:21",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894471": [
        {
            "ioc_value": "196.251.121.124:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-04 19:44:59",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894468": [
        {
            "ioc_value": "185.227.152.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-04 19:44:36",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894463": [
        {
            "ioc_value": "172.81.132.156:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-04 19:44:17",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894461": [
        {
            "ioc_value": "155.138.215.87:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-04 19:43:56",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894383": [
        {
            "ioc_value": "223.109.142.7:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-04 17:47:55",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894354": [
        {
            "ioc_value": "47.95.201.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-04 15:48:28",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894352": [
        {
            "ioc_value": "154.37.218.73:13580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-04 15:48:12",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894351": [
        {
            "ioc_value": "www.qkshhdjrbd.work",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-04 15:47:55",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894313": [
        {
            "ioc_value": "angkasa138wins.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-09-04 12:51:59",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1894314": [
        {
            "ioc_value": "angkasa138win.site",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-09-04 12:51:59",
            "last_seen_utc": "2026-10-09 21:02:40",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1894258": [
        {
            "ioc_value": "94.103.1.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-04 09:48:50",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894256": [
        {
            "ioc_value": "93.233.109.96:51125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-04 09:48:49",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894248": [
        {
            "ioc_value": "158.94.209.209:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-04 09:44:24",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894246": [
        {
            "ioc_value": "154.211.89.86:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-04 09:44:14",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1894163": [
        {
            "ioc_value": "137.184.108.14:6929",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-09-04 06:42:43",
            "last_seen_utc": "2026-10-11 03:41:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d434e284e35b431db9f91100113f649a,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1894001": [
        {
            "ioc_value": "43.155.9.112:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-03 21:05:05",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1893891": [
        {
            "ioc_value": "89.185.84.164:23189",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-03 20:17:38",
            "last_seen_utc": "2026-10-11 03:33:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,J06082026uyasd,Remcos",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1893985": [
        {
            "ioc_value": "93.233.109.96:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-03 19:47:07",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893984": [
        {
            "ioc_value": "76.164.192.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-03 19:46:47",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893977": [
        {
            "ioc_value": "198.23.237.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-03 19:44:54",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893975": [
        {
            "ioc_value": "192.253.226.78:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-03 19:44:42",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893971": [
        {
            "ioc_value": "173.249.197.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-03 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893968": [
        {
            "ioc_value": "158.94.211.158:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-03 19:43:57",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893959": [
        {
            "ioc_value": "102.220.160.117:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-09-03 19:43:05",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893903": [
        {
            "ioc_value": "46.151.182.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-03 15:05:07",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1893806": [
        {
            "ioc_value": "47.113.206.140:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-03 11:48:34",
            "last_seen_utc": "2026-10-09 14:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893805": [
        {
            "ioc_value": "43.155.9.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-03 11:48:32",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893803": [
        {
            "ioc_value": "154.94.224.35:2095",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-03 11:48:21",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893804": [
        {
            "ioc_value": "154.94.224.35:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-03 11:48:21",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893782": [
        {
            "ioc_value": "217.60.195.34:18631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-03 10:13:22",
            "last_seen_utc": "2026-10-11 02:10:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,WhiteRemote32",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1893768": [
        {
            "ioc_value": "158.94.211.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-03 09:44:01",
            "last_seen_utc": "2026-10-11 08:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893767": [
        {
            "ioc_value": "144.31.51.6:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-03 09:43:43",
            "last_seen_utc": "2026-10-11 09:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893634": [
        {
            "ioc_value": "217.60.195.210:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-09-03 05:39:23",
            "last_seen_utc": "2026-10-11 06:18:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1893627": [
        {
            "ioc_value": "165.99.43.101:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-02 23:47:27",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893626": [
        {
            "ioc_value": "103.119.47.222:35203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-02 23:47:15",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893499": [
        {
            "ioc_value": "20.2.140.201:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-09-02 19:45:46",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893498": [
        {
            "ioc_value": "185.212.128.169:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-02 19:45:00",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893496": [
        {
            "ioc_value": "167.17.47.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-09-02 19:44:34",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893491": [
        {
            "ioc_value": "135.84.210.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 19:44:04",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893490": [
        {
            "ioc_value": "104.143.46.142:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893488": [
        {
            "ioc_value": "102.220.160.198:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-02 19:43:17",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893215": [
        {
            "ioc_value": "45.11.230.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 15:23:44",
            "last_seen_utc": "2026-10-10 08:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1893184": [
        {
            "ioc_value": "194.32.149.129:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-02 13:05:07",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1893170": [
        {
            "ioc_value": "180.76.250.42:1996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-02 11:48:22",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893151": [
        {
            "ioc_value": "56.69.248.141:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 09:46:41",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893150": [
        {
            "ioc_value": "56.69.232.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 09:46:40",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893147": [
        {
            "ioc_value": "45.139.104.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 09:46:21",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893146": [
        {
            "ioc_value": "43.133.164.200:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-09-02 09:46:17",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893144": [
        {
            "ioc_value": "185.212.128.168:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-02 09:44:28",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893142": [
        {
            "ioc_value": "158.69.213.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-02 09:43:56",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893141": [
        {
            "ioc_value": "153.75.235.15:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-09-02 09:43:47",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1893019": [
        {
            "ioc_value": "45.139.104.204:55009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-02 07:10:50",
            "last_seen_utc": "2026-10-11 09:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1892657": [
        {
            "ioc_value": "77.83.39.141:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 19:46:26",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892653": [
        {
            "ioc_value": "31.76.125.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 19:45:46",
            "last_seen_utc": "2026-10-09 18:44:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892648": [
        {
            "ioc_value": "196.251.121.124:2008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 19:44:41",
            "last_seen_utc": "2026-10-11 09:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892643": [
        {
            "ioc_value": "194.9.6.35:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 19:44:37",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892641": [
        {
            "ioc_value": "192.253.226.78:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892642": [
        {
            "ioc_value": "192.253.226.78:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892622": [
        {
            "ioc_value": "114.66.27.110:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-09-01 19:05:04",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1892547": [
        {
            "ioc_value": "102.220.160.198:5444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-01 14:05:06",
            "last_seen_utc": "2026-10-09 18:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1892499": [
        {
            "ioc_value": "68.178.202.150:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-09-01 13:38:46",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1892418": [
        {
            "ioc_value": "109.172.89.209:40016",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-09-01 09:43:25",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892415": [
        {
            "ioc_value": "104.207.93.167:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-09-01 09:43:13",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892414": [
        {
            "ioc_value": "102.220.160.198:5333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-01 09:43:05",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1892358": [
        {
            "ioc_value": "104.254.90.162:28471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-09-01 07:22:54",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1892310": [
        {
            "ioc_value": "102.220.160.198:5222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-09-01 06:05:08",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891989": [
        {
            "ioc_value": "45.142.31.82:52125",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-31 19:46:18",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891981": [
        {
            "ioc_value": "104.143.46.142:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-31 19:43:13",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891980": [
        {
            "ioc_value": "104.143.46.142:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-31 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891979": [
        {
            "ioc_value": "102.220.160.198:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-31 19:43:05",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891821": [
        {
            "ioc_value": "192.99.70.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-31 09:45:32",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891818": [
        {
            "ioc_value": "129.80.106.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-31 09:43:42",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891594": [
        {
            "ioc_value": "150.158.102.111:85",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 23:05:06",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891556": [
        {
            "ioc_value": "109.236.50.145:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:06",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891554": [
        {
            "ioc_value": "109.236.50.145:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-30 20:05:05",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891538": [
        {
            "ioc_value": "194.59.30.96:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-30 19:44:35",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891537": [
        {
            "ioc_value": "185.112.59.115:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-30 19:44:14",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891534": [
        {
            "ioc_value": "160.119.69.30:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 19:43:51",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891529": [
        {
            "ioc_value": "144.31.106.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-30 19:43:36",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891530": [
        {
            "ioc_value": "144.31.106.168:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-30 19:43:36",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891490": [
        {
            "ioc_value": "http://zonxh.shop:7728/reports",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-30 15:55:19",
            "last_seen_utc": "2026-10-09 16:14:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/44fbba738f24e417236317f4efd260be890bcc745d6d9919a91b7015f84c402f/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891406": [
        {
            "ioc_value": "46.151.182.98:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-30 09:46:48",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891400": [
        {
            "ioc_value": "194.59.30.96:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-30 09:44:54",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891340": [
        {
            "ioc_value": "188.212.158.203:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-30 06:05:05",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1891222": [
        {
            "ioc_value": "47.86.9.253:10982",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 23:47:01",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891167": [
        {
            "ioc_value": "38.180.250.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-29 19:46:14",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891164": [
        {
            "ioc_value": "3.113.147.16:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 19:46:03",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891160": [
        {
            "ioc_value": "194.9.6.35:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:48",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891161": [
        {
            "ioc_value": "194.9.6.35:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-29 19:44:48",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891158": [
        {
            "ioc_value": "132.226.72.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 19:43:33",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891021": [
        {
            "ioc_value": "https://playmounthdom.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-29 14:08:52",
            "last_seen_utc": "2026-10-11 09:28:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,printer,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1891033": [
        {
            "ioc_value": "162.251.92.64:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-29 11:48:21",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891001": [
        {
            "ioc_value": "45.61.177.135:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-29 09:46:28",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890999": [
        {
            "ioc_value": "45.125.67.196:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-29 09:46:20",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1891000": [
        {
            "ioc_value": "45.125.67.196:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-29 09:46:20",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890998": [
        {
            "ioc_value": "220.154.128.196:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 09:45:55",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890995": [
        {
            "ioc_value": "169.58.180.142:30300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-29 09:44:07",
            "last_seen_utc": "2026-10-10 18:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890991": [
        {
            "ioc_value": "103.116.52.203:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-29 09:43:05",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890912": [
        {
            "ioc_value": "43.133.164.200:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-29 03:05:06",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1890815": [
        {
            "ioc_value": "91.92.241.38:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 19:46:31",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890814": [
        {
            "ioc_value": "87.58.199.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-28 19:46:27",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890797": [
        {
            "ioc_value": "102.220.160.231:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-28 19:43:04",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1890556": [
        {
            "ioc_value": "162.251.92.64:18888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-28 11:47:52",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889870": [
        {
            "ioc_value": "20.115.227.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-28 09:45:14",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889741": [
        {
            "ioc_value": "https://kiprihorycom.com/work/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-08-28 06:00:11",
            "last_seen_utc": "2026-10-11 09:38:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889507": [
        {
            "ioc_value": "5.230.201.54:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:47:08",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889501": [
        {
            "ioc_value": "192.229.115.243:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:44:53",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889497": [
        {
            "ioc_value": "185.212.128.90:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-27 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889498": [
        {
            "ioc_value": "185.212.128.96:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-27 19:44:38",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889487": [
        {
            "ioc_value": "134.122.187.68:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889488": [
        {
            "ioc_value": "134.122.187.68:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889489": [
        {
            "ioc_value": "134.122.187.68:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:39",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889484": [
        {
            "ioc_value": "104.243.248.63:302",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 19:43:14",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889483": [
        {
            "ioc_value": "103.54.153.49:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 19:43:09",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889307": [
        {
            "ioc_value": "109.248.151.101:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 14:54:26",
            "last_seen_utc": "2026-10-10 20:35:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Remcos,RemoteHost",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1889245": [
        {
            "ioc_value": "8.162.1.240:10087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:55",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889244": [
        {
            "ioc_value": "47.79.21.106:45678",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:51",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889243": [
        {
            "ioc_value": "39.97.57.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:44",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889239": [
        {
            "ioc_value": "106.15.10.2:11111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:21",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889240": [
        {
            "ioc_value": "106.15.10.2:6789",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:21",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889238": [
        {
            "ioc_value": "c-proxy-xjmkjgbsdn.cn-hangzhou.fcapp.run",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 11:48:13",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889205": [
        {
            "ioc_value": "185.34.147.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 10:05:10",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889206": [
        {
            "ioc_value": "45.61.170.105:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-27 10:05:10",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1889180": [
        {
            "ioc_value": "56.69.251.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:47:06",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889178": [
        {
            "ioc_value": "217.60.195.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-27 09:46:14",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889172": [
        {
            "ioc_value": "2.27.203.59:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-27 09:45:16",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889171": [
        {
            "ioc_value": "199.245.176.147:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-27 09:45:14",
            "last_seen_utc": "2026-10-11 08:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889127": [
        {
            "ioc_value": "217.60.195.34:18622",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-27 08:50:41",
            "last_seen_utc": "2026-10-11 04:04:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1be4ef70585595235b1f6b4890552228382101ba41226661aa6a86585e5fc458/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1889097": [
        {
            "ioc_value": "46.151.182.98:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-27 08:38:09",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "HypeAgent",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1889025": [
        {
            "ioc_value": "137.220.151.95:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-27 07:27:24",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888598": [
        {
            "ioc_value": "193.233.126.164:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:39",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888597": [
        {
            "ioc_value": "193.233.126.164:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:38",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888593": [
        {
            "ioc_value": "192.229.115.246:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888594": [
        {
            "ioc_value": "192.229.115.246:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888595": [
        {
            "ioc_value": "192.229.115.254:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888596": [
        {
            "ioc_value": "192.229.115.254:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:36",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888592": [
        {
            "ioc_value": "192.229.115.243:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-26 21:44:35",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888486": [
        {
            "ioc_value": "137.220.151.95:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-26 20:05:06",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1888477": [
        {
            "ioc_value": "49.232.135.25:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-26 19:46:20",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888473": [
        {
            "ioc_value": "199.245.176.147:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 19:44:42",
            "last_seen_utc": "2026-10-10 18:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888472": [
        {
            "ioc_value": "193.111.117.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-26 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888470": [
        {
            "ioc_value": "188.23.175.25:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-08-26 19:44:28",
            "last_seen_utc": "2026-10-11 08:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888459": [
        {
            "ioc_value": "8.163.98.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-26 19:05:08",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1888255": [
        {
            "ioc_value": "137.220.151.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-26 14:05:05",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1888159": [
        {
            "ioc_value": "107.175.88.79:30305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 12:03:30",
            "last_seen_utc": "2026-10-10 18:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888108": [
        {
            "ioc_value": "64.89.160.77:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-26 09:46:43",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,HypeAgent",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888107": [
        {
            "ioc_value": "49.235.130.208:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-26 09:46:34",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888104": [
        {
            "ioc_value": "38.147.188.28:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-26 09:46:11",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888101": [
        {
            "ioc_value": "193.233.220.65:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-26 09:44:43",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888090": [
        {
            "ioc_value": "104.105.15.96:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-26 09:43:10",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888089": [
        {
            "ioc_value": "101.99.92.134:4788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:43:04",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1888082": [
        {
            "ioc_value": "199.245.176.147:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-26 09:23:04",
            "last_seen_utc": "2026-10-10 18:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1888008": [
        {
            "ioc_value": "193.160.32.138:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-26 07:05:10",
            "last_seen_utc": "2026-10-11 08:17:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1887929": [
        {
            "ioc_value": "176.65.144.177:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-26 03:05:07",
            "last_seen_utc": "2026-10-11 09:44:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1887849": [
        {
            "ioc_value": "ck.erloro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-25 21:46:58",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887616": [
        {
            "ioc_value": "213.35.118.205:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 19:45:14",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887590": [
        {
            "ioc_value": "208.167.245.124:9993",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-25 19:05:06",
            "last_seen_utc": "2026-10-10 00:15:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1887525": [
        {
            "ioc_value": "217.60.195.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-10-11 09:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887526": [
        {
            "ioc_value": "193.233.126.164:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887527": [
        {
            "ioc_value": "192.229.115.243:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887528": [
        {
            "ioc_value": "192.229.115.243:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:08",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887523": [
        {
            "ioc_value": "217.60.195.25:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 17:15:07",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887235": [
        {
            "ioc_value": "38.147.185.54:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-25 15:16:32",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887208": [
        {
            "ioc_value": "192.229.115.254:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:43",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887209": [
        {
            "ioc_value": "192.229.115.254:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:42",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887210": [
        {
            "ioc_value": "192.229.115.246:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:42",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887211": [
        {
            "ioc_value": "192.229.115.246:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-25 15:00:41",
            "last_seen_utc": "2026-10-11 09:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1887142": [
        {
            "ioc_value": "185.254.99.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-08-25 14:16:38",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/solostalking/status/2092239178801242415",
            "tags": "Overlord,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1887000": [
        {
            "ioc_value": "2.27.202.130:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-25 13:05:06",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1886720": [
        {
            "ioc_value": "http://31.76.30.6/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-25 09:41:59",
            "last_seen_utc": "2026-10-11 09:29:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,StealC,stealer,tst100",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1886718": [
        {
            "ioc_value": "121.4.38.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-25 08:52:09",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1886342": [
        {
            "ioc_value": "154.201.82.105:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-24 17:37:46",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1885899": [
        {
            "ioc_value": "43.140.219.182:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-24 05:05:06",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885677": [
        {
            "ioc_value": "acsdomaindsadas.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-23 23:46:32",
            "last_seen_utc": "2026-10-10 10:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885593": [
        {
            "ioc_value": "194.9.6.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-23 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1885206": [
        {
            "ioc_value": "154.198.49.31:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-23 11:05:04",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885183": [
        {
            "ioc_value": "wingji.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-23 09:12:27",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885180": [
        {
            "ioc_value": "89.144.53.144:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-23 09:05:05",
            "last_seen_utc": "2026-10-10 08:45:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885147": [
        {
            "ioc_value": "indogenband.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-23 06:40:27",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885116": [
        {
            "ioc_value": "tnphomes.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-23 05:01:28",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885112": [
        {
            "ioc_value": "textandfonts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-23 04:35:55",
            "last_seen_utc": "2026-10-09 21:02:50",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1885087": [
        {
            "ioc_value": "mississippicannabisschool.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885088": [
        {
            "ioc_value": "oraclepacificltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885089": [
        {
            "ioc_value": "productstudio.me",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885090": [
        {
            "ioc_value": "psicologialorenalonso.es",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885091": [
        {
            "ioc_value": "sergiomarquesillustration.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885092": [
        {
            "ioc_value": "smec.group",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-10 04:59:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885093": [
        {
            "ioc_value": "tabrettbethell.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885095": [
        {
            "ioc_value": "thamyresheros.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885096": [
        {
            "ioc_value": "thinkomdigital.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885097": [
        {
            "ioc_value": "vipseniorplacement.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885098": [
        {
            "ioc_value": "wellthyco.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885099": [
        {
            "ioc_value": "william-c.360elevate.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:29",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885077": [
        {
            "ioc_value": "agenciaarco.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885078": [
        {
            "ioc_value": "agenciadetraduccion.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885080": [
        {
            "ioc_value": "bassprosurvey.store",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885081": [
        {
            "ioc_value": "corporaciongoldengroup.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885083": [
        {
            "ioc_value": "drrhodrimartin.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1885085": [
        {
            "ioc_value": "innovatransport.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-23 03:19:28",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,fake-plugin,hw-fingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1884305": [
        {
            "ioc_value": "93.152.223.39:28447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-22 09:47:02",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1884299": [
        {
            "ioc_value": "137.184.139.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-22 09:43:35",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883963": [
        {
            "ioc_value": "31.57.184.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-21 19:46:05",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883799": [
        {
            "ioc_value": "20.74.145.114:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-21 13:05:05",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883785": [
        {
            "ioc_value": "156.225.18.45:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-21 11:47:46",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883717": [
        {
            "ioc_value": "185.34.147.35:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883716": [
        {
            "ioc_value": "185.34.147.34:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:41",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883715": [
        {
            "ioc_value": "185.34.147.33:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 09:44:40",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883714": [
        {
            "ioc_value": "185.212.129.143:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-21 09:44:34",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883706": [
        {
            "ioc_value": "121.127.253.146:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-21 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883546": [
        {
            "ioc_value": "31.70.81.171:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-21 06:05:09",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "8560,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1883456": [
        {
            "ioc_value": "5.230.201.54:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883457": [
        {
            "ioc_value": "5.230.201.54:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-20 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883153": [
        {
            "ioc_value": "143.246.216.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2026-08-20 14:10:36",
            "last_seen_utc": "2026-10-11 09:49:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1883148": [
        {
            "ioc_value": "80.190.77.86:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 14:05:06",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883107": [
        {
            "ioc_value": "80.190.77.86:2000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 12:05:05",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883096": [
        {
            "ioc_value": "80.190.77.86:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-20 10:05:07",
            "last_seen_utc": "2026-10-11 08:45:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883087": [
        {
            "ioc_value": "4.193.136.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 09:46:04",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1883050": [
        {
            "ioc_value": "43.134.42.247:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 09:05:06",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1883010": [
        {
            "ioc_value": "4.193.136.143:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-20 08:05:08",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1882912": [
        {
            "ioc_value": "1.14.104.208:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-20 05:41:15",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/1.14.104.208#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1882792": [
        {
            "ioc_value": "fincloudsolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-19 23:32:13",
            "last_seen_utc": "2026-10-09 21:02:43",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1882677": [
        {
            "ioc_value": "95.133.166.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-19 19:46:59",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882675": [
        {
            "ioc_value": "38.247.165.127:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:46:01",
            "last_seen_utc": "2026-10-10 08:44:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882674": [
        {
            "ioc_value": "34.186.150.169:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:45:55",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882673": [
        {
            "ioc_value": "27.124.36.136:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:45:50",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882672": [
        {
            "ioc_value": "209.99.188.193:43222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 19:44:57",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882665": [
        {
            "ioc_value": "185.34.147.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:44:28",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882661": [
        {
            "ioc_value": "164.90.205.13:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-19 19:43:59",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882660": [
        {
            "ioc_value": "155.2.192.251:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:43:48",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882658": [
        {
            "ioc_value": "118.107.5.200:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:43:24",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882655": [
        {
            "ioc_value": "104.243.248.63:301",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882654": [
        {
            "ioc_value": "103.43.11.40:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-19 19:43:08",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1882470": [
        {
            "ioc_value": "www.masartech.io",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-19 17:52:47",
            "last_seen_utc": "2026-10-10 12:49:08",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1882376": [
        {
            "ioc_value": "134.209.112.52:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-19 15:05:06",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881976": [
        {
            "ioc_value": "tragroup.co.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-19 10:44:31",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1881948": [
        {
            "ioc_value": "94.20.141.82:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-19 09:46:53",
            "last_seen_utc": "2026-10-11 09:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881929": [
        {
            "ioc_value": "185.212.129.129:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-19 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1881771": [
        {
            "ioc_value": "38.247.165.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-19 07:13:58",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/38.247.165.127#443",
            "tags": "asyncrat,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1881764": [
        {
            "ioc_value": "192.169.176.54:449",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-19 07:11:04",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/192.169.176.54#449",
            "tags": "c2,havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1881751": [
        {
            "ioc_value": "192.169.176.54:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-19 07:09:22",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/192.169.176.54#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1881369": [
        {
            "ioc_value": "84.38.129.111:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.hype_agent",
            "malware_alias": null,
            "malware_printable": "HypeAgent",
            "first_seen_utc": "2026-08-19 06:06:07",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://infosec.exchange/@RecklessPush38671/117118098460752628",
            "tags": "C2,Censys,HypeAgent",
            "anonymous": 0,
            "reporter": "Overkill1984zzz"
        }
    ],
    "1881458": [
        {
            "ioc_value": "amouzeshgahahora.ir",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-19 06:05:49",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "https://x.com/skocherhan/status/2089834462951408044",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1880756": [
        {
            "ioc_value": "149.202.227.107:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 12:03:39",
            "last_seen_utc": "2026-10-11 08:43:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/149.202.227.107#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1880702": [
        {
            "ioc_value": "68.178.205.17:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-18 12:01:44",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/68.178.205.17#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1880291": [
        {
            "ioc_value": "23.148.212.123:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-18 11:48:07",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880290": [
        {
            "ioc_value": "ossb6.oss-cn-beijing.aliyuncs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-18 11:47:40",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880248": [
        {
            "ioc_value": "95.216.220.204:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-18 09:47:49",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880246": [
        {
            "ioc_value": "68.178.202.150:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:47:23",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880247": [
        {
            "ioc_value": "68.178.205.17:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:47:23",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880242": [
        {
            "ioc_value": "31.56.209.245:5088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-18 09:46:30",
            "last_seen_utc": "2026-10-11 09:45:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880236": [
        {
            "ioc_value": "192.169.176.54:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-18 09:44:53",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880234": [
        {
            "ioc_value": "186.169.88.130:5011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-18 09:44:48",
            "last_seen_utc": "2026-10-10 08:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1880231": [
        {
            "ioc_value": "185.212.128.51:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-18 09:44:40",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878822": [
        {
            "ioc_value": "38.76.183.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-18 07:05:10",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1878618": [
        {
            "ioc_value": "217.60.195.226:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:45:42",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878619": [
        {
            "ioc_value": "217.60.195.226:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:45:42",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878610": [
        {
            "ioc_value": "164.160.187.69:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 19:44:00",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878609": [
        {
            "ioc_value": "159.223.145.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-17 19:43:56",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878598": [
        {
            "ioc_value": "118.107.5.200:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:23",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1878599": [
        {
            "ioc_value": "118.107.5.200:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 19:43:23",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877749": [
        {
            "ioc_value": "86.48.16.94:3200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 09:47:39",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877748": [
        {
            "ioc_value": "83.136.211.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 09:47:35",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877744": [
        {
            "ioc_value": "217.60.195.226:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-17 09:46:26",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877742": [
        {
            "ioc_value": "193.32.162.108:4432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 09:45:13",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877740": [
        {
            "ioc_value": "178.128.14.67:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-17 09:44:35",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877739": [
        {
            "ioc_value": "169.58.180.142:30400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-17 09:44:22",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877737": [
        {
            "ioc_value": "107.173.160.185:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-17 09:43:20",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877664": [
        {
            "ioc_value": "34.150.91.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-17 06:05:05",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1877545": [
        {
            "ioc_value": "103.217.186.180:55554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-17 05:37:58",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1877531": [
        {
            "ioc_value": "23.148.212.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-16 23:47:35",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877335": [
        {
            "ioc_value": "94.26.0.7:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-16 19:46:47",
            "last_seen_utc": "2026-10-11 09:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877332": [
        {
            "ioc_value": "68.183.248.32:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-16 19:46:27",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877331": [
        {
            "ioc_value": "51.79.169.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 19:46:17",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877325": [
        {
            "ioc_value": "178.172.173.84:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-16 19:44:15",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877056": [
        {
            "ioc_value": "217.60.195.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:45:25",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1877052": [
        {
            "ioc_value": "135.136.147.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-16 09:43:30",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876823": [
        {
            "ioc_value": "91.236.230.143:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 19:46:52",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876814": [
        {
            "ioc_value": "45.154.98.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-15 19:46:12",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876809": [
        {
            "ioc_value": "217.60.195.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:43",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876810": [
        {
            "ioc_value": "217.60.195.40:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:43",
            "last_seen_utc": "2026-10-11 09:45:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876808": [
        {
            "ioc_value": "217.60.195.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 19:45:42",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876805": [
        {
            "ioc_value": "185.34.147.35:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:33",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876803": [
        {
            "ioc_value": "185.34.147.33:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876804": [
        {
            "ioc_value": "185.34.147.34:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876802": [
        {
            "ioc_value": "185.34.147.32:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:31",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876801": [
        {
            "ioc_value": "185.34.147.31:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 19:44:30",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876320": [
        {
            "ioc_value": "91.92.243.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-15 09:46:30",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876316": [
        {
            "ioc_value": "45.154.98.207:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-15 09:45:51",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876313": [
        {
            "ioc_value": "194.182.87.116:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:44:31",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876309": [
        {
            "ioc_value": "155.94.150.221:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-15 09:43:45",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876307": [
        {
            "ioc_value": "144.124.234.128:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-15 09:43:37",
            "last_seen_utc": "2026-10-11 09:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876285": [
        {
            "ioc_value": "93.95.227.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-15 09:05:05",
            "last_seen_utc": "2026-10-11 09:46:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1876083": [
        {
            "ioc_value": "91.92.43.103:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-14 19:46:41",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876081": [
        {
            "ioc_value": "64.89.161.196:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-14 19:46:22",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1876072": [
        {
            "ioc_value": "2.27.248.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-14 19:44:41",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874667": [
        {
            "ioc_value": "103.51.145.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-14 09:43:07",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1874208": [
        {
            "ioc_value": "20.187.120.42:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-14 06:05:07",
            "last_seen_utc": "2026-10-09 14:45:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1874132": [
        {
            "ioc_value": "willowbrooktownhouse.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-14 03:00:48",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 90,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873841": [
        {
            "ioc_value": "217.60.195.226:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-13 19:45:43",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873610": [
        {
            "ioc_value": "119.29.122.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-13 11:05:07",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873568": [
        {
            "ioc_value": "203.161.55.41:7691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-13 09:45:09",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873559": [
        {
            "ioc_value": "185.34.147.31:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873560": [
        {
            "ioc_value": "185.34.147.32:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-13 09:44:39",
            "last_seen_utc": "2026-10-11 09:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873444": [
        {
            "ioc_value": "198.199.86.166:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-13 06:05:05",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1873335": [
        {
            "ioc_value": "120.55.93.58:10092",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-12 23:46:54",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873272": [
        {
            "ioc_value": "89.110.91.35:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-12 19:46:45",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873254": [
        {
            "ioc_value": "23.148.228.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 19:45:40",
            "last_seen_utc": "2026-10-11 09:45:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1873148": [
        {
            "ioc_value": "http://95.135.181.73/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-12 17:32:12",
            "last_seen_utc": "2026-10-11 09:48:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,Mewwski,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1872703": [
        {
            "ioc_value": "172.245.23.153:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-12 09:44:15",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872696": [
        {
            "ioc_value": "13.236.153.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-08-12 09:43:32",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872489": [
        {
            "ioc_value": "89.127.233.194:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-12 00:05:05",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1872484": [
        {
            "ioc_value": "159.75.123.199:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 23:47:15",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872411": [
        {
            "ioc_value": "154.40.62.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-11 19:43:44",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872329": [
        {
            "ioc_value": "cf.lala1.lat",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 15:46:46",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872210": [
        {
            "ioc_value": "47.94.224.229:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 11:48:37",
            "last_seen_utc": "2026-10-09 14:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872157": [
        {
            "ioc_value": "23.94.252.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-11 09:46:08",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1872144": [
        {
            "ioc_value": "104.243.248.63:300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-11 09:43:17",
            "last_seen_utc": "2026-10-11 09:00:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871881": [
        {
            "ioc_value": "192.252.185.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 20:05:05",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871806": [
        {
            "ioc_value": "38.97.63.243:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-08-10 19:31:02",
            "last_seen_utc": "2026-10-11 05:06:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871851": [
        {
            "ioc_value": "192.252.179.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 19:05:07",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871717": [
        {
            "ioc_value": "38.97.63.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-08-10 14:24:09",
            "last_seen_utc": "2026-10-11 04:04:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871626": [
        {
            "ioc_value": "98.191.191.44:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-10 09:46:58",
            "last_seen_utc": "2026-10-09 18:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871392": [
        {
            "ioc_value": "49.235.153.53:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-09 19:45:52",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871390": [
        {
            "ioc_value": "45.140.204.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-09 19:45:38",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871391": [
        {
            "ioc_value": "45.140.204.12:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-09 19:45:38",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871389": [
        {
            "ioc_value": "217.60.77.60:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:45:16",
            "last_seen_utc": "2026-10-11 09:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871267": [
        {
            "ioc_value": "139.162.113.221:64321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871263": [
        {
            "ioc_value": "134.122.132.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:29",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871110": [
        {
            "ioc_value": "1.92.135.168:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:43:01",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871093": [
        {
            "ioc_value": "37.72.168.212:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 18:05:07",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870713": [
        {
            "ioc_value": "88.129.145.223:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-08 09:46:32",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870712": [
        {
            "ioc_value": "68.178.202.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:46:21",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870709": [
        {
            "ioc_value": "45.157.117.186:27487",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:45:54",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870697": [
        {
            "ioc_value": "134.122.132.35:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:43:26",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870641": [
        {
            "ioc_value": "192.169.176.54:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 07:05:05",
            "last_seen_utc": "2026-10-11 09:44:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870610": [
        {
            "ioc_value": "68.178.205.17:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 04:05:05",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870252": [
        {
            "ioc_value": "43.135.34.69:43911",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-07 19:45:42",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870246": [
        {
            "ioc_value": "185.212.128.59:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 19:44:13",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870231": [
        {
            "ioc_value": "43.138.116.60:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 19:05:06",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869851": [
        {
            "ioc_value": "43.138.116.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 13:05:06",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869772": [
        {
            "ioc_value": "185.212.128.170:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 09:44:18",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869770": [
        {
            "ioc_value": "154.40.62.125:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-07 09:43:42",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869767": [
        {
            "ioc_value": "103.249.116.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:43:06",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869550": [
        {
            "ioc_value": "154.37.154.36:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:38",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869323": [
        {
            "ioc_value": "134.122.132.28:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-06 09:43:25",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869309": [
        {
            "ioc_value": "161.248.179.98:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-06 08:45:44",
            "last_seen_utc": "2026-10-11 01:59:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1785db0cee90d76004983b741c8a059d9e1b3811765723ec38bff1da10c4e5f3/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869054": [
        {
            "ioc_value": "72.14.136.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:46:50",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869046": [
        {
            "ioc_value": "185.212.129.31:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:31",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869044": [
        {
            "ioc_value": "185.212.129.170:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:30",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869042": [
        {
            "ioc_value": "185.212.128.124:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:28",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869036": [
        {
            "ioc_value": "130.12.181.96:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-05 19:43:28",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869029": [
        {
            "ioc_value": "134.209.146.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:05:05",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868828": [
        {
            "ioc_value": "47.83.3.103:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:40",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868826": [
        {
            "ioc_value": "209.200.246.194:16556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:30",
            "last_seen_utc": "2026-10-09 14:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868823": [
        {
            "ioc_value": "acac.hopto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:46:59",
            "last_seen_utc": "2026-10-09 14:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868757": [
        {
            "ioc_value": "65.1.70.222:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:46:52",
            "last_seen_utc": "2026-10-11 09:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868756": [
        {
            "ioc_value": "64.227.159.29:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:51",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868755": [
        {
            "ioc_value": "64.20.61.215:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:46:50",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868752": [
        {
            "ioc_value": "43.135.26.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:46:19",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868744": [
        {
            "ioc_value": "186.244.227.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:34",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868740": [
        {
            "ioc_value": "186.169.88.130:5012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-10-10 18:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868741": [
        {
            "ioc_value": "186.169.88.130:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-10-10 08:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868742": [
        {
            "ioc_value": "186.244.227.104:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868743": [
        {
            "ioc_value": "186.244.227.27:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868736": [
        {
            "ioc_value": "185.212.129.70:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868737": [
        {
            "ioc_value": "185.212.129.89:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868734": [
        {
            "ioc_value": "172.81.132.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:44:12",
            "last_seen_utc": "2026-10-11 09:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868732": [
        {
            "ioc_value": "160.20.109.52:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:00",
            "last_seen_utc": "2026-10-11 09:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868636": [
        {
            "ioc_value": "43.108.51.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 06:05:05",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868570": [
        {
            "ioc_value": "222.255.215.42:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 23:47:37",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868504": [
        {
            "ioc_value": "80.96.109.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:46:26",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868501": [
        {
            "ioc_value": "31.76.96.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-04 19:45:42",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868315": [
        {
            "ioc_value": "217.60.195.193:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-04 12:55:43",
            "last_seen_utc": "2026-10-11 09:44:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9df545f9a40281bf7789feb875a6f2fa3334dc6bfda329e8bc55667d5bee4b0d/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868251": [
        {
            "ioc_value": "45.139.226.224:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:45:57",
            "last_seen_utc": "2026-10-11 09:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868250": [
        {
            "ioc_value": "27.124.36.136:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:45:40",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868110": [
        {
            "ioc_value": "39.105.213.209:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-04 06:05:09",
            "last_seen_utc": "2026-10-10 00:15:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867957": [
        {
            "ioc_value": "217.60.195.197:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:45:13",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867781": [
        {
            "ioc_value": "193.112.169.214:30727",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-03 09:44:27",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867534": [
        {
            "ioc_value": "27.124.36.153:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:35",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867533": [
        {
            "ioc_value": "217.60.77.60:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:28",
            "last_seen_utc": "2026-10-11 09:45:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866972": [
        {
            "ioc_value": "64.20.61.215:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 19:46:16",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866967": [
        {
            "ioc_value": "155.2.192.251:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:46",
            "last_seen_utc": "2026-10-11 08:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866966": [
        {
            "ioc_value": "139.199.160.80:32408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:31",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866964": [
        {
            "ioc_value": "106.53.107.131:30943",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866965": [
        {
            "ioc_value": "107.152.42.223:34321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866960": [
        {
            "ioc_value": "101.36.123.12:34321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866620": [
        {
            "ioc_value": "47.87.84.177:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:46:18",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866615": [
        {
            "ioc_value": "217.60.195.197:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:39",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866614": [
        {
            "ioc_value": "217.60.195.197:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:38",
            "last_seen_utc": "2026-10-11 09:45:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866374": [
        {
            "ioc_value": "103.214.146.46:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:28:01",
            "last_seen_utc": "2026-10-10 17:03:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866366": [
        {
            "ioc_value": "93.152.223.242:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-31 19:46:12",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866362": [
        {
            "ioc_value": "23.227.196.18:43655",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-31 19:45:14",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866361": [
        {
            "ioc_value": "194.62.248.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:21",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866359": [
        {
            "ioc_value": "185.174.102.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:09",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866358": [
        {
            "ioc_value": "167.172.142.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-31 19:43:52",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866017": [
        {
            "ioc_value": "27.124.36.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:45:48",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866015": [
        {
            "ioc_value": "209.99.190.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-31 09:44:55",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866008": [
        {
            "ioc_value": "13.205.246.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:43:27",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866007": [
        {
            "ioc_value": "104.243.248.63:3608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:43:15",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1865067": [
        {
            "ioc_value": "27.71.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:43",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "7552,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1864993": [
        {
            "ioc_value": "27.124.36.136:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864983": [
        {
            "ioc_value": "18.178.127.205:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:11",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864982": [
        {
            "ioc_value": "18.139.36.190:24610",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:10",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864979": [
        {
            "ioc_value": "132.226.72.148:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:26",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864973": [
        {
            "ioc_value": "103.53.80.201:3312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:09",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864706": [
        {
            "ioc_value": "93.152.223.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-30 09:46:46",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864704": [
        {
            "ioc_value": "50.114.184.63:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:18",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864703": [
        {
            "ioc_value": "50.114.184.63:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:17",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864702": [
        {
            "ioc_value": "46.151.182.16:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 09:46:11",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864701": [
        {
            "ioc_value": "27.124.36.151:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:45:43",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864698": [
        {
            "ioc_value": "2.27.248.116:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-30 09:44:36",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864696": [
        {
            "ioc_value": "173.199.70.174:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 09:44:06",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863590": [
        {
            "ioc_value": "67.210.97.40:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:46:10",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863583": [
        {
            "ioc_value": "27.124.36.151:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:45:30",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863584": [
        {
            "ioc_value": "27.124.36.151:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:45:30",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863575": [
        {
            "ioc_value": "185.212.128.207:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-29 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863569": [
        {
            "ioc_value": "154.194.50.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863567": [
        {
            "ioc_value": "142.93.52.11:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:43:33",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863562": [
        {
            "ioc_value": "103.97.131.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863378": [
        {
            "ioc_value": "14.225.212.124:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 11:47:01",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863344": [
        {
            "ioc_value": "84.201.20.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:46:02",
            "last_seen_utc": "2026-10-10 20:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863341": [
        {
            "ioc_value": "67.210.97.40:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:45:54",
            "last_seen_utc": "2026-10-11 09:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863339": [
        {
            "ioc_value": "23.94.252.80:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:45:17",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863308": [
        {
            "ioc_value": "5.253.86.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:27",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863304": [
        {
            "ioc_value": "45.192.211.63:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:16",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863299": [
        {
            "ioc_value": "27.124.36.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:00",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863298": [
        {
            "ioc_value": "27.124.36.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:59",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863255": [
        {
            "ioc_value": "193.164.5.4:9991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:02",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863163": [
        {
            "ioc_value": "victororsolin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-29 08:57:56",
            "last_seen_utc": "2026-10-11 05:21:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac,wordpress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1863070": [
        {
            "ioc_value": "sdc.contact",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-29 08:57:51",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac,wordpress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1863044": [
        {
            "ioc_value": "160.119.69.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:33",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862993": [
        {
            "ioc_value": "orionplus.biz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-29 08:57:07",
            "last_seen_utc": "2026-10-11 00:53:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac,wordpress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1862890": [
        {
            "ioc_value": "jacmedicalgt.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-29 08:56:59",
            "last_seen_utc": "2026-10-09 17:11:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac,wordpress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1862836": [
        {
            "ioc_value": "gazixpress.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-29 08:55:55",
            "last_seen_utc": "2026-10-10 20:20:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,Mac,wordpress",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1861777": [
        {
            "ioc_value": "45.192.211.7:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:09",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1862621": [
        {
            "ioc_value": "154.12.94.16:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 07:32:16",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861817": [
        {
            "ioc_value": "31.57.184.154:2504",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:34",
            "last_seen_utc": "2026-10-10 08:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861744": [
        {
            "ioc_value": "45.192.211.7:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861745": [
        {
            "ioc_value": "45.192.211.7:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861741": [
        {
            "ioc_value": "45.192.211.19:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861742": [
        {
            "ioc_value": "45.192.211.63:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861710": [
        {
            "ioc_value": "108.187.4.116:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861711": [
        {
            "ioc_value": "108.187.4.145:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861712": [
        {
            "ioc_value": "108.187.4.145:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861713": [
        {
            "ioc_value": "108.187.4.145:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861708": [
        {
            "ioc_value": "108.187.4.116:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861709": [
        {
            "ioc_value": "108.187.4.116:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861522": [
        {
            "ioc_value": "96.126.176.92:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:46:46",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861521": [
        {
            "ioc_value": "93.152.223.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:46:44",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861520": [
        {
            "ioc_value": "49.235.50.231:14486",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-28 09:46:12",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861516": [
        {
            "ioc_value": "23.94.252.87:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:45:42",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861515": [
        {
            "ioc_value": "23.94.252.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:45:41",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861508": [
        {
            "ioc_value": "157.245.228.139:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:43:54",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859646": [
        {
            "ioc_value": "centroculturalpuce.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-27 05:59:36",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "cf-hw-check,ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1859658": [
        {
            "ioc_value": "legacyconsulting.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-27 05:59:34",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "cf-hw-check,ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1859666": [
        {
            "ioc_value": "www.concreteasap.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-27 05:59:28",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "cf-hw-check,ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1859682": [
        {
            "ioc_value": "www.risefoundationngo.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-27 05:59:27",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "cf-hw-check,ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1859691": [
        {
            "ioc_value": "purecomfortcare.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-27 05:59:26",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "cf-hw-check,ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1859700": [
        {
            "ioc_value": "141.255.162.234:37422",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 23:45:57",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859680": [
        {
            "ioc_value": "47.113.98.42:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:46:16",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859678": [
        {
            "ioc_value": "dns1.dreamls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:45:45",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859679": [
        {
            "ioc_value": "dns2.dreamls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:45:45",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859428": [
        {
            "ioc_value": "rup-shor.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-26 20:18:05",
            "last_seen_utc": "2026-10-09 17:11:43",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1859381": [
        {
            "ioc_value": "physioasia.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-26 20:18:02",
            "last_seen_utc": "2026-10-09 18:01:21",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1859139": [
        {
            "ioc_value": "didigetthebestrate.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-26 20:17:50",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1858980": [
        {
            "ioc_value": "2.27.248.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-26 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857981": [
        {
            "ioc_value": "198.98.53.100:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-26 10:55:50",
            "last_seen_utc": "2026-10-10 04:27:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1858179": [
        {
            "ioc_value": "103.67.163.201:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-26 09:43:12",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857719": [
        {
            "ioc_value": "185.147.83.59:48321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:44:10",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857718": [
        {
            "ioc_value": "146.70.87.23:43225",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:43:34",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857716": [
        {
            "ioc_value": "141.255.164.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 19:43:29",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857715": [
        {
            "ioc_value": "103.67.163.201:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 19:43:11",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857313": [
        {
            "ioc_value": "31.76.96.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 09:45:30",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857314": [
        {
            "ioc_value": "31.76.96.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 09:45:30",
            "last_seen_utc": "2026-10-11 09:45:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857310": [
        {
            "ioc_value": "207.57.123.129:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:42",
            "last_seen_utc": "2026-10-11 09:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857303": [
        {
            "ioc_value": "119.28.212.86:44321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:43:20",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857302": [
        {
            "ioc_value": "103.67.163.201:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 09:43:10",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856912": [
        {
            "ioc_value": "87.251.64.204:63812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-24 19:45:44",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856908": [
        {
            "ioc_value": "23.94.252.7:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 19:44:59",
            "last_seen_utc": "2026-10-11 09:45:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856907": [
        {
            "ioc_value": "2.27.248.80:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 19:44:16",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856894": [
        {
            "ioc_value": "151.236.21.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-24 19:43:33",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856708": [
        {
            "ioc_value": "23.94.145.121:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 09:45:54",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856638": [
        {
            "ioc_value": "198.98.53.100:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-24 06:20:07",
            "last_seen_utc": "2026-10-11 02:12:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1856292": [
        {
            "ioc_value": "93.152.224.94:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:46:19",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856291": [
        {
            "ioc_value": "93.152.223.159:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:46:18",
            "last_seen_utc": "2026-10-11 09:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856288": [
        {
            "ioc_value": "2.27.248.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:28",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856285": [
        {
            "ioc_value": "2.27.248.232:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856286": [
        {
            "ioc_value": "2.27.248.236:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856287": [
        {
            "ioc_value": "2.27.248.72:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-10-11 09:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856213": [
        {
            "ioc_value": "www.ai2.qzz.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:18",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855968": [
        {
            "ioc_value": "2.27.248.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 09:44:27",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855923": [
        {
            "ioc_value": "174.138.9.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-23 08:05:05",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855460": [
        {
            "ioc_value": "43.228.157.252:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:45:15",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855453": [
        {
            "ioc_value": "137.184.163.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 19:43:25",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855451": [
        {
            "ioc_value": "12.187.175.73:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:21",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855382": [
        {
            "ioc_value": "43.134.38.218:4543",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 17:05:52",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855246": [
        {
            "ioc_value": "20.200.61.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:44:24",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855239": [
        {
            "ioc_value": "132.145.210.148:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:43:25",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855047": [
        {
            "ioc_value": "86.48.16.94:30100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 19:46:20",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855046": [
        {
            "ioc_value": "85.208.69.45:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-21 19:46:19",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855038": [
        {
            "ioc_value": "2.27.122.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-21 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854903": [
        {
            "ioc_value": "152.136.253.101:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-21 12:05:05",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1854871": [
        {
            "ioc_value": "185.33.86.141:29292",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 09:44:16",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854504": [
        {
            "ioc_value": "220.154.3.197:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:45:02",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854503": [
        {
            "ioc_value": "203.83.238.164:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:44:22",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854498": [
        {
            "ioc_value": "151.243.101.44:21343",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:37",
            "last_seen_utc": "2026-10-11 09:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854496": [
        {
            "ioc_value": "14.22.75.6:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854497": [
        {
            "ioc_value": "14.22.75.6:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854495": [
        {
            "ioc_value": "12.202.180.13:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 19:43:22",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854200": [
        {
            "ioc_value": "220.154.3.197:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:45:09",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854198": [
        {
            "ioc_value": "203.83.238.164:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854199": [
        {
            "ioc_value": "203.83.238.164:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854196": [
        {
            "ioc_value": "185.212.131.28:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:09",
            "last_seen_utc": "2026-10-09 18:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854195": [
        {
            "ioc_value": "185.212.128.155:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:07",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853923": [
        {
            "ioc_value": "cucumber-oslo.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-07-19 20:39:00",
            "last_seen_utc": "2026-10-10 21:59:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7502ed3956c621d9442e51343a9d9fd22fb080d1a9edcffc1386901ebb4da9ec/",
            "tags": "NWHStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853898": [
        {
            "ioc_value": "14.22.75.6:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 19:43:26",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853717": [
        {
            "ioc_value": "185.147.83.58:64213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 09:44:11",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853334": [
        {
            "ioc_value": "45.55.98.175:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-18 09:46:14",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852912": [
        {
            "ioc_value": "20.2.87.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 21:05:07",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852641": [
        {
            "ioc_value": "188.166.40.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:44:30",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852491": [
        {
            "ioc_value": "203.91.75.89:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 09:47:53",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851397": [
        {
            "ioc_value": "14.29.160.181:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 04:05:05",
            "last_seen_utc": "2026-10-11 09:46:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851289": [
        {
            "ioc_value": "64.23.182.12:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:46:03",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850971": [
        {
            "ioc_value": "74.0.32.137:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 09:46:18",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850827": [
        {
            "ioc_value": "160.25.72.34:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 07:00:55",
            "last_seen_utc": "2026-10-11 08:01:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/15a9a83377456de32bbdb36a8ec3113bf8ca07c884a45617c9410f80990ed4b3/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850748": [
        {
            "ioc_value": "175.210.184.125:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 22:05:04",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1850665": [
        {
            "ioc_value": "175.210.184.125:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 18:05:07",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1849979": [
        {
            "ioc_value": "85.8.149.156:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:45:28",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849976": [
        {
            "ioc_value": "37.235.54.142:53236",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-13 19:44:54",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849974": [
        {
            "ioc_value": "23.27.52.106:28736",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-13 19:44:48",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849967": [
        {
            "ioc_value": "185.212.131.27:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-13 19:43:57",
            "last_seen_utc": "2026-10-09 18:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849604": [
        {
            "ioc_value": "103.214.146.46:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-13 07:03:02",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/blob/main/aisuru/README.md",
            "tags": "airashi,aisuru,botnet,c2,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1849540": [
        {
            "ioc_value": "103.67.163.108:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 03:40:49",
            "last_seen_utc": "2026-10-11 08:33:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/09cc1c77657400e803310dd7ba58a91854fb275e5b29adf53a6ee2827f848366/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848944": [
        {
            "ioc_value": "38.54.8.74:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:25",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848936": [
        {
            "ioc_value": "107.172.90.117:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:43:18",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848772": [
        {
            "ioc_value": "82.158.229.189:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848773": [
        {
            "ioc_value": "82.158.229.30:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848771": [
        {
            "ioc_value": "82.158.229.143:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:04",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848755": [
        {
            "ioc_value": "1.14.234.68:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848583": [
        {
            "ioc_value": "137.220.194.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 09:46:53",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848580": [
        {
            "ioc_value": "69.10.49.136:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 09:46:08",
            "last_seen_utc": "2026-10-11 09:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848358": [
        {
            "ioc_value": "8.134.70.73:6111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:33",
            "last_seen_utc": "2026-10-10 14:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847999": [
        {
            "ioc_value": "101.42.255.92:2234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 11:46:34",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847977": [
        {
            "ioc_value": "101.42.255.92:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 10:05:08",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847970": [
        {
            "ioc_value": "74.0.32.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:46:14",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847959": [
        {
            "ioc_value": "104.250.161.126:2061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:43:16",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847905": [
        {
            "ioc_value": "119.45.160.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 06:05:05",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847753": [
        {
            "ioc_value": "37.72.172.58:4212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:45:23",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847751": [
        {
            "ioc_value": "213.209.159.91:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:44:37",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847750": [
        {
            "ioc_value": "212.46.38.117:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 19:44:36",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847743": [
        {
            "ioc_value": "115.42.60.122:7912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 19:43:21",
            "last_seen_utc": "2026-10-09 18:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847229": [
        {
            "ioc_value": "compocel.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-07-09 15:33:13",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "etherhiding,Polygon,victim",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1847068": [
        {
            "ioc_value": "203.91.75.89:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 11:47:21",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847000": [
        {
            "ioc_value": "5.230.201.242:1995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:46:09",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846995": [
        {
            "ioc_value": "37.72.172.58:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:45:45",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846984": [
        {
            "ioc_value": "176.120.22.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-07-09 09:44:00",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846977": [
        {
            "ioc_value": "157.173.195.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:45",
            "last_seen_utc": "2026-10-11 09:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846849": [
        {
            "ioc_value": "193.29.13.44:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 02:05:05",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1846736": [
        {
            "ioc_value": "213.209.159.91:4556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-08 19:44:32",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846733": [
        {
            "ioc_value": "164.68.123.50:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 19:43:45",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845839": [
        {
            "ioc_value": "hayvavillage.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-07 05:21:29",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1845851": [
        {
            "ioc_value": "www.bluebarnestates.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-07-07 05:21:18",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCF",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1845588": [
        {
            "ioc_value": "38.46.218.34:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-07-06 10:58:18",
            "last_seen_utc": "2026-10-11 09:12:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1845504": [
        {
            "ioc_value": "222.167.211.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:45:29",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845502": [
        {
            "ioc_value": "203.161.57.75:8234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:44:36",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845499": [
        {
            "ioc_value": "2.27.122.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:44:33",
            "last_seen_utc": "2026-10-11 09:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845497": [
        {
            "ioc_value": "173.249.41.141:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:59",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845493": [
        {
            "ioc_value": "143.198.120.167:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:32",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845343": [
        {
            "ioc_value": "134.209.41.160:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-06 04:05:04",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1845294": [
        {
            "ioc_value": "31.220.93.222:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 19:45:18",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845293": [
        {
            "ioc_value": "194.26.192.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-05 19:44:18",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845011": [
        {
            "ioc_value": "111.229.248.198:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 13:33:27",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844960": [
        {
            "ioc_value": "http://91.202.233.134/4d95d68e3fc64f3bbbf5.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-07-05 09:50:45",
            "last_seen_utc": "2026-10-11 08:37:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1095cf2951bbc8b1ecd33798afad192449a102aa1b976fb60bf566a08d693587/",
            "tags": "stealc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844840": [
        {
            "ioc_value": "92.4.65.88:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-04 19:45:47",
            "last_seen_utc": "2026-10-11 09:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844400": [
        {
            "ioc_value": "http://tolail.xyz:7538",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-04 04:21:01",
            "last_seen_utc": "2026-10-11 06:56:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/be5b469852253e4c60925777c114b46e7fca797bd21dc39b2f3774589ce0909a/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843418": [
        {
            "ioc_value": "220.154.3.197:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 11:44:21",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Mythic,MythicC2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1843465": [
        {
            "ioc_value": "82.165.79.60:12001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843466": [
        {
            "ioc_value": "82.165.79.60:12002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-10-11 09:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843463": [
        {
            "ioc_value": "70.34.251.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-02 09:45:42",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843455": [
        {
            "ioc_value": "159.65.42.43:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-02 09:43:38",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843453": [
        {
            "ioc_value": "141.94.121.162:6060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 09:43:24",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840722": [
        {
            "ioc_value": "119.91.243.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 08:05:06",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840704": [
        {
            "ioc_value": "43.144.19.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 07:05:06",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840379": [
        {
            "ioc_value": "193.24.123.25:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:21",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840375": [
        {
            "ioc_value": "138.124.240.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840376": [
        {
            "ioc_value": "138.124.240.76:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840377": [
        {
            "ioc_value": "138.124.240.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840372": [
        {
            "ioc_value": "107.172.22.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 19:43:15",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840352": [
        {
            "ioc_value": "41.216.189.153:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 17:45:13",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840351": [
        {
            "ioc_value": "2.26.1.177:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:44:15",
            "last_seen_utc": "2026-10-11 09:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840347": [
        {
            "ioc_value": "172.94.18.103:69",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 17:43:45",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840271": [
        {
            "ioc_value": "152.32.132.177:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:11",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839238": [
        {
            "ioc_value": "updatesrv.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839239": [
        {
            "ioc_value": "web-analyzer-serv32.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839220": [
        {
            "ioc_value": "45.92.158.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 09:45:31",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838799": [
        {
            "ioc_value": "45.150.38.95:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-28 19:44:54",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838660": [
        {
            "ioc_value": "155.94.163.75:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838629": [
        {
            "ioc_value": "47.86.184.71:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:40",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838628": [
        {
            "ioc_value": "test.officeplustool.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:01",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838579": [
        {
            "ioc_value": "thespeedyhomeoffer.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-27 08:48:26",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCloudflare",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1838580": [
        {
            "ioc_value": "trendomart.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-27 08:48:26",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCloudflare",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1838570": [
        {
            "ioc_value": "hollytree-transport.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-27 08:48:25",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCloudflare",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1838558": [
        {
            "ioc_value": "airtek.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-27 08:48:24",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,FakeCloudflare",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1838532": [
        {
            "ioc_value": "8.152.212.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 07:05:05",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838183": [
        {
            "ioc_value": "82.165.79.60:1336",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-26 19:45:25",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838123": [
        {
            "ioc_value": "https://k1h.hopesm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-10-10 06:25:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838124": [
        {
            "ioc_value": "k1h.hopesm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-10-10 06:25:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837449": [
        {
            "ioc_value": "50.114.184.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:17",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837476": [
        {
            "ioc_value": "45.192.211.64:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837477": [
        {
            "ioc_value": "45.192.211.64:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837478": [
        {
            "ioc_value": "45.192.211.64:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-10-11 09:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837490": [
        {
            "ioc_value": "5.230.201.220:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:53:55",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837441": [
        {
            "ioc_value": "45.192.211.59:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:46",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837442": [
        {
            "ioc_value": "45.192.211.59:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:45",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837443": [
        {
            "ioc_value": "45.192.211.59:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:44",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837265": [
        {
            "ioc_value": "45.192.211.63:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 08:21:13",
            "last_seen_utc": "2026-10-11 09:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837243": [
        {
            "ioc_value": "169.239.128.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:08:03",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837080": [
        {
            "ioc_value": "146.190.80.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 19:43:22",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836876": [
        {
            "ioc_value": "physiothetics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-24 11:04:21",
            "last_seen_utc": "2026-10-11 01:13:11",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,injected,Polygon",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1836781": [
        {
            "ioc_value": "38.207.177.71:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-24 09:45:14",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836771": [
        {
            "ioc_value": "107.172.140.187:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836768": [
        {
            "ioc_value": "102.220.160.250:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836769": [
        {
            "ioc_value": "102.220.160.250:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-24 09:43:04",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836662": [
        {
            "ioc_value": "156.239.47.147:4221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-23 19:43:29",
            "last_seen_utc": "2026-10-11 09:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836655": [
        {
            "ioc_value": "102.220.160.250:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-23 19:43:03",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835556": [
        {
            "ioc_value": "102.220.160.250:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:03",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835280": [
        {
            "ioc_value": "vitimadetransito.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-21 22:58:30",
            "last_seen_utc": "2026-10-11 05:21:58",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding,Polygon,Remus",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1834051": [
        {
            "ioc_value": "103.153.254.32:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-19 09:43:05",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834041": [
        {
            "ioc_value": "110.42.232.120:8897",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-06-19 09:00:14",
            "last_seen_utc": "2026-10-11 02:49:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833750": [
        {
            "ioc_value": "54.38.94.225:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-18 09:45:43",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833649": [
        {
            "ioc_value": "livelaughfite.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-18 07:23:07",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833655": [
        {
            "ioc_value": "nabane.com.mx",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-18 07:23:04",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833660": [
        {
            "ioc_value": "panelmienbac.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-18 07:23:02",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833672": [
        {
            "ioc_value": "volunteerskonect.ca",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-18 07:22:55",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833673": [
        {
            "ioc_value": "westpointfulfillment.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-18 07:22:55",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833682": [
        {
            "ioc_value": "yimmunotek.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-18 07:22:34",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833622": [
        {
            "ioc_value": "106.13.189.138:56000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 23:45:31",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833500": [
        {
            "ioc_value": "20.39.60.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-17 17:00:15",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832958": [
        {
            "ioc_value": "abelmomaroc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 05:45:27",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833333": [
        {
            "ioc_value": "www.sabine-kley.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:01",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833337": [
        {
            "ioc_value": "www.tr88.uno",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:01",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833313": [
        {
            "ioc_value": "voyaimpresionarte.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833314": [
        {
            "ioc_value": "wbworkshops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833316": [
        {
            "ioc_value": "webexpress.cl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833318": [
        {
            "ioc_value": "westlandconsultants.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833322": [
        {
            "ioc_value": "www.citymoversmagazine.com.ng",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833323": [
        {
            "ioc_value": "www.corterosantico.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833324": [
        {
            "ioc_value": "www.danialrad.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833326": [
        {
            "ioc_value": "www.geekpsychologyseries.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:43:00",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833295": [
        {
            "ioc_value": "theoptimaemhltd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:59",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833298": [
        {
            "ioc_value": "toilettage-muzillac.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:59",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833300": [
        {
            "ioc_value": "trecoshop.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:59",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833301": [
        {
            "ioc_value": "tritantech.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:59",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833309": [
        {
            "ioc_value": "vanguard-bridge-global.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:59",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833281": [
        {
            "ioc_value": "swabina.co.id",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:58",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833284": [
        {
            "ioc_value": "synergysurveys.online",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:58",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833285": [
        {
            "ioc_value": "taiwandonutsoh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:58",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833286": [
        {
            "ioc_value": "tamposit.pl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:58",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833287": [
        {
            "ioc_value": "techwizzardz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:58",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833253": [
        {
            "ioc_value": "querenhapuque.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833257": [
        {
            "ioc_value": "rebelwithareason.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833262": [
        {
            "ioc_value": "renovapqs.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833266": [
        {
            "ioc_value": "sabatravels.com.pk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833269": [
        {
            "ioc_value": "scripterx.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833270": [
        {
            "ioc_value": "sgsolicitors.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833271": [
        {
            "ioc_value": "sham-top.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:57",
            "last_seen_utc": "2026-10-09 16:19:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833242": [
        {
            "ioc_value": "olivefuneralhome.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:56",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833243": [
        {
            "ioc_value": "ouagayaar.bf",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:56",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833223": [
        {
            "ioc_value": "mcliokays.co.zw",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:55",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833225": [
        {
            "ioc_value": "mediosdigitalesdelnorte.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:55",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833228": [
        {
            "ioc_value": "metroreportase.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:55",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833201": [
        {
            "ioc_value": "jaimeresendiz.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:54",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833203": [
        {
            "ioc_value": "jensencollector.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:54",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833205": [
        {
            "ioc_value": "judyprescottmarshall.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:54",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833207": [
        {
            "ioc_value": "kingdomdelight.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:54",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833208": [
        {
            "ioc_value": "kinshiphomesmaintenance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:54",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833211": [
        {
            "ioc_value": "lmwstudios.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:54",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833181": [
        {
            "ioc_value": "futureconnectgroup.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833184": [
        {
            "ioc_value": "gmiconsulting.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833187": [
        {
            "ioc_value": "gospelofwork.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833188": [
        {
            "ioc_value": "gracedrivenlife.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833189": [
        {
            "ioc_value": "hapvidaonline.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833192": [
        {
            "ioc_value": "homefrontprojects.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833193": [
        {
            "ioc_value": "htxvanthanhphat.vn",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833194": [
        {
            "ioc_value": "hux.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833195": [
        {
            "ioc_value": "iamstudent.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:53",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833158": [
        {
            "ioc_value": "drfelipearnaud.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833161": [
        {
            "ioc_value": "ebyeos.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833166": [
        {
            "ioc_value": "elegantshoppingbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833167": [
        {
            "ioc_value": "elite-agri.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833174": [
        {
            "ioc_value": "fabidi.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833175": [
        {
            "ioc_value": "fassett.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833141": [
        {
            "ioc_value": "database.lupusinforum.it",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:51",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833143": [
        {
            "ioc_value": "deep4sleep.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:51",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833145": [
        {
            "ioc_value": "die-enthusiasten.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:51",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833147": [
        {
            "ioc_value": "diolaser.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:51",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833150": [
        {
            "ioc_value": "domarisconcepts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:51",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833119": [
        {
            "ioc_value": "caminhandodeus.com.br",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:50",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833131": [
        {
            "ioc_value": "codropssarl.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:50",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833133": [
        {
            "ioc_value": "consorzioaion.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:50",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833137": [
        {
            "ioc_value": "covernats.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:50",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833102": [
        {
            "ioc_value": "ashifct.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:49",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833110": [
        {
            "ioc_value": "boiseriesmd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:49",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833118": [
        {
            "ioc_value": "cameradalat.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:49",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833090": [
        {
            "ioc_value": "alprosperu.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:48",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833091": [
        {
            "ioc_value": "americaspets.tv",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:48",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833095": [
        {
            "ioc_value": "andeusa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-06-17 04:42:48",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,CloudflareHardwareFingerprinting",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1833008": [
        {
            "ioc_value": "212.14.244.222:807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-10-10 09:30:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833009": [
        {
            "ioc_value": "212.14.244.222:809",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-10-11 08:17:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832762": [
        {
            "ioc_value": "119.59.118.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:43:12",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832647": [
        {
            "ioc_value": "39.106.205.6:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 11:00:15",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832399": [
        {
            "ioc_value": "23.95.170.223:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:46:19",
            "last_seen_utc": "2026-10-10 10:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832398": [
        {
            "ioc_value": "cs.tpedu2metricstw.dpdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:45:49",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832323": [
        {
            "ioc_value": "89.42.134.220:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:54",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832320": [
        {
            "ioc_value": "8.210.84.56:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:45:46",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832313": [
        {
            "ioc_value": "131.143.251.246:53921",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:43:17",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832163": [
        {
            "ioc_value": "89.42.134.220:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:45:30",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831995": [
        {
            "ioc_value": "64.225.102.218:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:45:07",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831987": [
        {
            "ioc_value": "185.207.154.11:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:43",
            "last_seen_utc": "2026-10-11 09:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831838": [
        {
            "ioc_value": "45.153.127.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-06-13 19:45:04",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831732": [
        {
            "ioc_value": "89.42.134.220:1991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:46:08",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831722": [
        {
            "ioc_value": "130.185.82.117:5641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:18",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831720": [
        {
            "ioc_value": "108.181.115.254:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-10-09 18:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831721": [
        {
            "ioc_value": "108.181.115.254:7045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-10-09 18:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831717": [
        {
            "ioc_value": "101.33.202.134:9989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:02",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830387": [
        {
            "ioc_value": "192.3.139.18:15221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:43:50",
            "last_seen_utc": "2026-10-11 09:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830307": [
        {
            "ioc_value": "172.94.18.103:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-11 14:00:17",
            "last_seen_utc": "2026-10-10 08:43:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830007": [
        {
            "ioc_value": "45.87.53.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:05",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830006": [
        {
            "ioc_value": "120.55.3.157:10000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:04",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829899": [
        {
            "ioc_value": "193.135.137.240:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:51",
            "last_seen_utc": "2026-10-11 09:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829892": [
        {
            "ioc_value": "170.39.185.141:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:32",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825846": [
        {
            "ioc_value": "107.175.87.234:65321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 09:43:10",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825788": [
        {
            "ioc_value": "34.92.128.98:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 07:18:53",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825721": [
        {
            "ioc_value": "http://contentremixrr.com:6584",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-10 06:19:43",
            "last_seen_utc": "2026-10-09 19:03:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2d0a4aba600f61d29e6de6bafedb6e3e42118d619e98004a4ed51eaef99ef1e8/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825703": [
        {
            "ioc_value": "8.163.59.20:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 06:00:25",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825678": [
        {
            "ioc_value": "218.244.142.4:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:38",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825614": [
        {
            "ioc_value": "45.87.53.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 20:00:17",
            "last_seen_utc": "2026-10-11 08:17:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825613": [
        {
            "ioc_value": "46.151.182.16:1011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:44:51",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824508": [
        {
            "ioc_value": "209.200.246.194:17568",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-07 23:45:14",
            "last_seen_utc": "2026-10-09 14:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824254": [
        {
            "ioc_value": "209.99.188.193:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:44:10",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824247": [
        {
            "ioc_value": "137.184.163.27:5613",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-07 09:43:16",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824098": [
        {
            "ioc_value": "77.83.39.141:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-07 07:23:22",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1824099": [
        {
            "ioc_value": "77.83.39.141:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-07 07:23:22",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1824130": [
        {
            "ioc_value": "46.151.182.243:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:44:30",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823853": [
        {
            "ioc_value": "https://pas.sm188star.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-10-10 06:26:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823854": [
        {
            "ioc_value": "pas.sm188star.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-10-10 06:26:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822674": [
        {
            "ioc_value": "dev.useimage.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-05 05:14:52",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822600": [
        {
            "ioc_value": "34.202.161.96:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:28",
            "last_seen_utc": "2026-10-11 09:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822599": [
        {
            "ioc_value": "updates.fisgloval.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:07",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822516": [
        {
            "ioc_value": "101.37.210.236:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-04 19:00:16",
            "last_seen_utc": "2026-10-09 10:31:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821798": [
        {
            "ioc_value": "13.236.153.60:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-03 15:24:07",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820398": [
        {
            "ioc_value": "154.38.114.115:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:19",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820327": [
        {
            "ioc_value": "64.89.160.44:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 15:04:22",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820291": [
        {
            "ioc_value": "64.176.73.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-31 09:45:39",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820290": [
        {
            "ioc_value": "31.57.184.154:2503",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 09:44:59",
            "last_seen_utc": "2026-10-11 08:45:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820214": [
        {
            "ioc_value": "64.89.160.44:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 06:48:28",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "205759,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1820043": [
        {
            "ioc_value": "38.54.63.135:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:23",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819906": [
        {
            "ioc_value": "43.140.219.30:7112",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-29 19:45:33",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819896": [
        {
            "ioc_value": "162.248.225.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819897": [
        {
            "ioc_value": "162.248.225.165:8603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819786": [
        {
            "ioc_value": "118.89.79.131:6528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:33",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819406": [
        {
            "ioc_value": "91.215.85.212:45423",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:09",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819405": [
        {
            "ioc_value": "85.209.90.132:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:05",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819402": [
        {
            "ioc_value": "43.133.165.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:23",
            "last_seen_utc": "2026-10-11 09:45:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819396": [
        {
            "ioc_value": "202.95.8.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-10-11 09:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819397": [
        {
            "ioc_value": "202.95.8.98:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-10-11 08:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819225": [
        {
            "ioc_value": "91.200.84.198:8515",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:55",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819220": [
        {
            "ioc_value": "18.162.155.202:3350",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-27 19:43:47",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819218": [
        {
            "ioc_value": "104.243.248.63:1807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 19:43:09",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819146": [
        {
            "ioc_value": "8.134.70.73:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:43",
            "last_seen_utc": "2026-10-10 14:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819104": [
        {
            "ioc_value": "ns1.deepsekapi.cn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 13:46:00",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818956": [
        {
            "ioc_value": "8.163.49.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1818872": [
        {
            "ioc_value": "155.102.136.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-26 19:43:28",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818696": [
        {
            "ioc_value": "193.24.123.160:45631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:02",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818605": [
        {
            "ioc_value": "103.17.38.43:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-05-26 08:35:01",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1818480": [
        {
            "ioc_value": "47.108.25.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:18",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818434": [
        {
            "ioc_value": "37.77.150.174:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:52",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818433": [
        {
            "ioc_value": "37.77.150.174:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:51",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818431": [
        {
            "ioc_value": "202.95.8.92:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-25 19:44:05",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818053": [
        {
            "ioc_value": "45.154.12.150:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:49",
            "last_seen_utc": "2026-10-11 09:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817829": [
        {
            "ioc_value": "172.94.18.103:75",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:05:15",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817758": [
        {
            "ioc_value": "https://cyy.turbo88ml.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:09",
            "last_seen_utc": "2026-10-10 06:26:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817757": [
        {
            "ioc_value": "cyy.turbo88ml.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:08",
            "last_seen_utc": "2026-10-10 06:26:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817704": [
        {
            "ioc_value": "151.236.20.3:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-23 19:43:35",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817663": [
        {
            "ioc_value": "101.126.10.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:56",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817238": [
        {
            "ioc_value": "54.187.35.128:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:45:08",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817235": [
        {
            "ioc_value": "31.57.184.154:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:40",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817159": [
        {
            "ioc_value": "143.14.9.56:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 08:11:29",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "adaptix_v1.2,adaptixc2,c2,panel",
            "anonymous": 0,
            "reporter": "Lenny_3BO"
        }
    ],
    "1816737": [
        {
            "ioc_value": "221.207.101.175:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-20 19:44:32",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816735": [
        {
            "ioc_value": "167.17.47.118:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:30",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816585": [
        {
            "ioc_value": "51.15.8.6:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-20 09:45:05",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816431": [
        {
            "ioc_value": "91.202.233.214:44123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:45:18",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816427": [
        {
            "ioc_value": "31.57.184.154:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:44:36",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816296": [
        {
            "ioc_value": "176.120.22.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-05-19 09:43:37",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816100": [
        {
            "ioc_value": "38.147.189.199:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-18 19:44:31",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815927": [
        {
            "ioc_value": "163.181.46.56:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-18 09:43:30",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815827": [
        {
            "ioc_value": "evamotion.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-05-18 07:06:08",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "ClickFix,compromised,fake-plugin,WordPress",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815397": [
        {
            "ioc_value": "45.155.69.153:43345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:45:35",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815133": [
        {
            "ioc_value": "34.69.130.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 19:44:19",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815073": [
        {
            "ioc_value": "pgo.fatherchrismas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-10-10 06:26:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1815074": [
        {
            "ioc_value": "https://pgo.fatherchrismas.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-10-10 06:26:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1812126": [
        {
            "ioc_value": "84.46.251.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-14 09:51:34",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811385": [
        {
            "ioc_value": "104.243.248.63:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 09:43:06",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811187": [
        {
            "ioc_value": "mpd.pegasus-77.biz.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-10-10 06:27:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811188": [
        {
            "ioc_value": "https://mpd.pegasus-77.biz.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-10-10 06:27:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811186": [
        {
            "ioc_value": "117.50.184.221:10080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:16",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811129": [
        {
            "ioc_value": "64.199.252.59:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:45:07",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811128": [
        {
            "ioc_value": "51.77.54.76:6769",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:45:01",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810965": [
        {
            "ioc_value": "89.42.134.220:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:45:15",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810955": [
        {
            "ioc_value": "185.242.245.27:44875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:35",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810414": [
        {
            "ioc_value": "31.57.184.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:31",
            "last_seen_utc": "2026-10-11 09:45:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810408": [
        {
            "ioc_value": "189.34.188.6:5406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810409": [
        {
            "ioc_value": "189.34.188.6:5407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-10-11 09:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810170": [
        {
            "ioc_value": "57.158.27.132:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 09:44:56",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809754": [
        {
            "ioc_value": "213.130.25.141:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-09 19:43:46",
            "last_seen_utc": "2026-10-11 09:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809750": [
        {
            "ioc_value": "168.144.89.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-09 19:43:24",
            "last_seen_utc": "2026-10-11 09:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809033": [
        {
            "ioc_value": "180.97.214.70:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-08 19:43:28",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808650": [
        {
            "ioc_value": "45.56.91.55:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808637": [
        {
            "ioc_value": "178.104.186.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:13",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808628": [
        {
            "ioc_value": "113.31.118.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808286": [
        {
            "ioc_value": "101.33.225.32:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:32",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807842": [
        {
            "ioc_value": "154.18.238.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:14",
            "last_seen_utc": "2026-10-11 09:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806228": [
        {
            "ioc_value": "154.219.115.123:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:43",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805766": [
        {
            "ioc_value": "82.165.79.60:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:13",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805765": [
        {
            "ioc_value": "82.165.79.60:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:12",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804719": [
        {
            "ioc_value": "124.95.172.200:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:06",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803894": [
        {
            "ioc_value": "59.152.212.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 18:43:53",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803841": [
        {
            "ioc_value": "103.79.79.105:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:03",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803670": [
        {
            "ioc_value": "frr.ambil-disini.web.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-10-10 06:27:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803671": [
        {
            "ioc_value": "https://frr.ambil-disini.web.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-10-10 06:27:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803513": [
        {
            "ioc_value": "64.89.163.114:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-10-11 09:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803500": [
        {
            "ioc_value": "47.103.106.26:2333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-10-11 09:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803486": [
        {
            "ioc_value": "20.2.83.254:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 08:43:23",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803279": [
        {
            "ioc_value": "91.202.233.153:43555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803276": [
        {
            "ioc_value": "85.155.186.2:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-10-11 09:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803262": [
        {
            "ioc_value": "79.135.160.20:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803254": [
        {
            "ioc_value": "62.81.188.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803246": [
        {
            "ioc_value": "46.101.77.223:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803239": [
        {
            "ioc_value": "45.155.69.175:42455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-10-11 09:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803240": [
        {
            "ioc_value": "45.56.91.55:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803235": [
        {
            "ioc_value": "45.125.67.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803232": [
        {
            "ioc_value": "43.142.77.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803233": [
        {
            "ioc_value": "43.142.77.170:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803234": [
        {
            "ioc_value": "43.160.225.40:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803218": [
        {
            "ioc_value": "222.255.100.119:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803219": [
        {
            "ioc_value": "23.227.203.6:42235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803222": [
        {
            "ioc_value": "31.57.184.154:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-10-11 09:45:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803211": [
        {
            "ioc_value": "216.107.208.250:10444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803215": [
        {
            "ioc_value": "219.142.15.101:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-10-11 09:45:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803216": [
        {
            "ioc_value": "220.231.47.163:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803217": [
        {
            "ioc_value": "221.130.42.19:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803205": [
        {
            "ioc_value": "208.249.244.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803206": [
        {
            "ioc_value": "209.151.145.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803174": [
        {
            "ioc_value": "185.212.129.23:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-10-11 09:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803178": [
        {
            "ioc_value": "185.213.20.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803179": [
        {
            "ioc_value": "185.242.245.120:42534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-10-11 09:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803167": [
        {
            "ioc_value": "182.255.45.114:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-10-11 09:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803162": [
        {
            "ioc_value": "178.16.52.22:8396",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-10-11 09:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803153": [
        {
            "ioc_value": "172.9.165.216:8096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803141": [
        {
            "ioc_value": "154.219.115.123:60001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-10-11 09:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803146": [
        {
            "ioc_value": "161.248.179.92:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803134": [
        {
            "ioc_value": "149.104.28.204:3656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803127": [
        {
            "ioc_value": "142.93.88.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:06",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803124": [
        {
            "ioc_value": "138.124.113.131:4211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803114": [
        {
            "ioc_value": "115.42.60.122:5440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803115": [
        {
            "ioc_value": "117.72.101.55:9520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803113": [
        {
            "ioc_value": "115.190.247.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1802897": [
        {
            "ioc_value": "82.156.219.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:45",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800528": [
        {
            "ioc_value": "http://pillow.riverbridge.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 19:14:08",
            "last_seen_utc": "2026-10-10 06:32:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800513": [
        {
            "ioc_value": "91.92.242.236:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:36:03",
            "last_seen_utc": "2026-10-11 09:44:58",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=91.92.242.236",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800509": [
        {
            "ioc_value": "pillow.riverbridge.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 18:19:19",
            "last_seen_utc": "2026-10-10 06:32:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2199baf11d50dd10555f8aec122178e03b62570fc0d4614a8e928978dc547154/",
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800411": [
        {
            "ioc_value": "http://91.92.242.236/oPvjr94jfe/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:11:00",
            "last_seen_utc": "2026-10-11 09:49:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "54e64e,amadey,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1800052": [
        {
            "ioc_value": "sa1atik.cn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.salatstealer",
            "malware_alias": null,
            "malware_printable": "SalatStealer",
            "first_seen_utc": "2026-04-25 16:07:23",
            "last_seen_utc": "2026-10-11 03:46:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/97fd78bc83c79dddeae4fd303e014b4db63c49fc2b507ef7a2f57066cbe9ca10/",
            "tags": "SalatStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1797248": [
        {
            "ioc_value": "psy.flise-mesteren.dk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:06",
            "last_seen_utc": "2026-10-10 06:27:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1797247": [
        {
            "ioc_value": "https://psy.flise-mesteren.dk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:01",
            "last_seen_utc": "2026-10-10 06:27:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796426": [
        {
            "ioc_value": "http://196.251.107.248/kont2rt/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-23 04:45:34",
            "last_seen_utc": "2026-10-11 09:16:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796068": [
        {
            "ioc_value": "wrath.bottlevacuum.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:13",
            "last_seen_utc": "2026-10-10 06:32:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796067": [
        {
            "ioc_value": "http://wrath.bottlevacuum.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:09",
            "last_seen_utc": "2026-10-10 06:32:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794910": [
        {
            "ioc_value": "39.100.66.238:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-20 10:52:12",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794232": [
        {
            "ioc_value": "91.92.241.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-19 11:04:19",
            "last_seen_utc": "2026-10-11 09:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "Lenny_3BO"
        }
    ],
    "1793617": [
        {
            "ioc_value": "ask.shurimaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:27",
            "last_seen_utc": "2026-10-10 06:27:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1793616": [
        {
            "ioc_value": "https://ask.shurimaster.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:25",
            "last_seen_utc": "2026-10-10 06:27:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792719": [
        {
            "ioc_value": "gusto.brothbridge.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:20",
            "last_seen_utc": "2026-10-10 06:30:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792718": [
        {
            "ioc_value": "http://gusto.brothbridge.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:17",
            "last_seen_utc": "2026-10-10 06:30:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792707": [
        {
            "ioc_value": "43.167.177.224:7778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:56:58",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792631": [
        {
            "ioc_value": "47.109.23.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 06:43:30",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791688": [
        {
            "ioc_value": "venom.summertunnel.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:17",
            "last_seen_utc": "2026-10-10 06:30:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791687": [
        {
            "ioc_value": "http://venom.summertunnel.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:13",
            "last_seen_utc": "2026-10-10 06:30:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1784558": [
        {
            "ioc_value": "47.104.248.7:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 06:34:43",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1783891": [
        {
            "ioc_value": "laurebessiere.fr",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-10 16:04:33",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1783375": [
        {
            "ioc_value": "39.102.125.11:4435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-09 14:48:47",
            "last_seen_utc": "2026-10-09 14:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782312": [
        {
            "ioc_value": "annamirror.design",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-07 13:40:56",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,WebDav",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1782124": [
        {
            "ioc_value": "1.15.76.39:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-07 07:17:26",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781907": [
        {
            "ioc_value": "43.139.108.161:8192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 18:49:49",
            "last_seen_utc": "2026-10-11 09:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1781292": [
        {
            "ioc_value": "webgleam.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-04 22:07:06",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1781225": [
        {
            "ioc_value": "111.230.217.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:05",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781224": [
        {
            "ioc_value": "109.244.130.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:01",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1780791": [
        {
            "ioc_value": "213.21.222.241:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-04 07:11:11",
            "last_seen_utc": "2026-10-11 09:44:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mythic,Shodan",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1774903": [
        {
            "ioc_value": "37.72.172.58:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-24 12:01:13",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774898": [
        {
            "ioc_value": "47.92.208.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-24 12:00:35",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.92.208.27",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774595": [
        {
            "ioc_value": "154.83.12.132:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 21:06:09",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1774088": [
        {
            "ioc_value": "23.227.199.67:42215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-23 04:01:28",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.199.67",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1773536": [
        {
            "ioc_value": "156.239.252.191:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-22 18:02:20",
            "last_seen_utc": "2026-10-11 09:46:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,C2,CobaltStrike,Shodan",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1773754": [
        {
            "ioc_value": "138.226.236.52:13212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-22 12:01:29",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/138.226.236.52",
            "tags": "AdaptixC2,AS205775,C2,censys,NEONCORENETWORKS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1772919": [
        {
            "ioc_value": "cryptonewskenya.co.ke",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-20 22:53:36",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,WebDav",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1772820": [
        {
            "ioc_value": "greatmastertrading.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-20 21:47:37",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,WebDAV",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1771791": [
        {
            "ioc_value": "8.136.13.87:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-20 00:02:12",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.136.13.87",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771713": [
        {
            "ioc_value": "167.17.47.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:47",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.17.47.121",
            "tags": "AdaptixC2,AS43180,C2,censys,TRUNKNETWORKS-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1769099": [
        {
            "ioc_value": "159.75.176.189:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-17 08:00:12",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.75.176.189",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1768102": [
        {
            "ioc_value": "laughing-octo.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.santa_stealer",
            "malware_alias": null,
            "malware_printable": "SantaStealer",
            "first_seen_utc": "2026-03-16 20:34:58",
            "last_seen_utc": "2026-10-09 12:13:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b875bf5d04c56cfc5d19c6e8a8b57943d089da702101dc5da81f63370f41e6dd/",
            "tags": "c2,SantaStealer",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1768644": [
        {
            "ioc_value": "35.179.229.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-16 20:01:10",
            "last_seen_utc": "2026-10-11 09:45:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.179.229.71",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1768638": [
        {
            "ioc_value": "64.227.105.70:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-16 20:01:02",
            "last_seen_utc": "2026-10-11 09:45:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.227.105.70",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1767990": [
        {
            "ioc_value": "43.155.169.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-16 12:00:11",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.155.169.245",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1766764": [
        {
            "ioc_value": "202.191.67.71:50003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-15 04:01:14",
            "last_seen_utc": "2026-10-11 09:44:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/202.191.67.71",
            "tags": "AdaptixC2,AS131262,C2,censys,KELNET-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1764276": [
        {
            "ioc_value": "46.151.182.205:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-13 04:01:11",
            "last_seen_utc": "2026-10-11 09:45:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.151.182.205",
            "tags": "AS205759,AsyncRAT,C2,censys,GHOSTYNETWORKS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1763737": [
        {
            "ioc_value": "130.12.182.209:9456",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-03-11 23:00:21",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260311-zw3w6adw5k",
            "tags": "quasar",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1763170": [
        {
            "ioc_value": "60.247.206.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 07:03:38",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1762492": [
        {
            "ioc_value": "107.172.3.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-10 00:01:13",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.3.15",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1761756": [
        {
            "ioc_value": "crispy-rusty.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.santa_stealer",
            "malware_alias": null,
            "malware_printable": "SantaStealer",
            "first_seen_utc": "2026-03-09 06:09:24",
            "last_seen_utc": "2026-10-09 12:13:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/a198aedff4f84588326b22aa1ff900f287a3e904f16f172a308c8affe9342f25/",
            "tags": "c2,SantaStealer",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1759331": [
        {
            "ioc_value": "194.36.178.53:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-06 00:01:40",
            "last_seen_utc": "2026-10-11 09:44:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.36.178.53",
            "tags": "AdaptixC2,AS200740,C2,censys,FIRST-SERVER-EU-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1758456": [
        {
            "ioc_value": "http://213.5.130.197",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:58",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758457": [
        {
            "ioc_value": "http://213.5.130.154",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:57",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758458": [
        {
            "ioc_value": "http://213.5.130.200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:56",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758459": [
        {
            "ioc_value": "http://213.5.130.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:55",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758460": [
        {
            "ioc_value": "http://213.5.130.179",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758461": [
        {
            "ioc_value": "http://213.5.130.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758006": [
        {
            "ioc_value": "70.153.18.45:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-04 04:01:12",
            "last_seen_utc": "2026-10-11 09:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/70.153.18.45",
            "tags": "AS8075,censys,EvilGoPhish,MICROSOFT-CORP-MSN-AS-BLOCK,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1756253": [
        {
            "ioc_value": "102.117.160.67:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-01 08:29:28",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/102.117.160.67#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1754671": [
        {
            "ioc_value": "115.190.250.28:5521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:01:08",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.250.28",
            "tags": "AS137718,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754344": [
        {
            "ioc_value": "23.88.110.42:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-02-24 23:00:43",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.88.110.42",
            "tags": "AS24940,C2,censys,HETZNER-AS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754120": [
        {
            "ioc_value": "analyticshore.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 15:14:37",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754165": [
        {
            "ioc_value": "metricspixel.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 15:14:15",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754171": [
        {
            "ioc_value": "pixelmetrics.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 15:14:10",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754178": [
        {
            "ioc_value": "169.40.135.36:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-24 12:02:30",
            "last_seen_utc": "2026-10-10 18:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/169.40.135.36",
            "tags": "AdaptixC2,AS209274,C2,censys,KRAKEN-NETWORK-ISP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1754159": [
        {
            "ioc_value": "googlanalitlcs.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:48:03",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754156": [
        {
            "ioc_value": "googlanalitlcs.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:46:56",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754153": [
        {
            "ioc_value": "googlanalitlcs.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:46:05",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754150": [
        {
            "ioc_value": "googlanalitlcs.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:44:50",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754147": [
        {
            "ioc_value": "webtracelab.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:43:28",
            "last_seen_utc": "2026-10-10 22:28:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754144": [
        {
            "ioc_value": "webpulsedata.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:42:30",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754141": [
        {
            "ioc_value": "siteinsights.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:40:50",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754135": [
        {
            "ioc_value": "datapointly.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:38:25",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754132": [
        {
            "ioc_value": "clickstream.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:37:34",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1754126": [
        {
            "ioc_value": "trackmetrica.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-24 11:35:20",
            "last_seen_utc": "2026-10-10 22:28:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix,EXT",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1753847": [
        {
            "ioc_value": "49.232.135.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:09",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/49.232.135.25",
            "tags": "AS45090,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751104": [
        {
            "ioc_value": "107.172.217.220:12096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 11:00:06",
            "last_seen_utc": "2026-10-10 10:45:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.217.220",
            "tags": "AS36352,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751080": [
        {
            "ioc_value": "163.181.208.79:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-20 08:46:17",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1749217": [
        {
            "ioc_value": "111.228.4.54:4455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-16 09:05:30",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.228.4.54#4455",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1748256": [
        {
            "ioc_value": "101.200.193.211:8086",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-14 15:11:17",
            "last_seen_utc": "2026-10-11 08:17:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1747540": [
        {
            "ioc_value": "gor.emiraride.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:35",
            "last_seen_utc": "2026-10-10 06:27:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747538": [
        {
            "ioc_value": "https://gor.emiraride.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:02",
            "last_seen_utc": "2026-10-10 06:27:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1743594": [
        {
            "ioc_value": "15.204.14.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-09 11:00:33",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1743395": [
        {
            "ioc_value": "1.15.25.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:41",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743391": [
        {
            "ioc_value": "106.52.208.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743392": [
        {
            "ioc_value": "106.13.137.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743393": [
        {
            "ioc_value": "101.43.2.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743394": [
        {
            "ioc_value": "101.133.148.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743388": [
        {
            "ioc_value": "115.190.178.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743389": [
        {
            "ioc_value": "114.132.150.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743390": [
        {
            "ioc_value": "110.40.176.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743386": [
        {
            "ioc_value": "120.48.50.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743387": [
        {
            "ioc_value": "117.72.214.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743381": [
        {
            "ioc_value": "124.223.199.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743382": [
        {
            "ioc_value": "124.221.32.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743383": [
        {
            "ioc_value": "124.220.48.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743384": [
        {
            "ioc_value": "124.220.164.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743385": [
        {
            "ioc_value": "121.41.167.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743378": [
        {
            "ioc_value": "152.136.139.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743379": [
        {
            "ioc_value": "129.204.103.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743380": [
        {
            "ioc_value": "124.223.47.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743374": [
        {
            "ioc_value": "172.245.215.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743375": [
        {
            "ioc_value": "165.154.125.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743376": [
        {
            "ioc_value": "156.233.233.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743377": [
        {
            "ioc_value": "154.201.91.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743370": [
        {
            "ioc_value": "38.190.224.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743371": [
        {
            "ioc_value": "222.255.214.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743372": [
        {
            "ioc_value": "192.252.187.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743373": [
        {
            "ioc_value": "178.16.52.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743365": [
        {
            "ioc_value": "43.139.146.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743366": [
        {
            "ioc_value": "43.133.41.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743367": [
        {
            "ioc_value": "42.192.49.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743368": [
        {
            "ioc_value": "39.107.85.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743369": [
        {
            "ioc_value": "39.106.144.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743363": [
        {
            "ioc_value": "47.100.168.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743364": [
        {
            "ioc_value": "43.139.169.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743362": [
        {
            "ioc_value": "47.111.146.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:30",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743358": [
        {
            "ioc_value": "47.243.175.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743359": [
        {
            "ioc_value": "47.239.188.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743360": [
        {
            "ioc_value": "47.122.30.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743361": [
        {
            "ioc_value": "47.122.1.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743356": [
        {
            "ioc_value": "61.166.154.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743357": [
        {
            "ioc_value": "49.235.177.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743353": [
        {
            "ioc_value": "81.70.255.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743354": [
        {
            "ioc_value": "81.69.98.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743355": [
        {
            "ioc_value": "8.210.78.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743351": [
        {
            "ioc_value": "83.229.126.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743352": [
        {
            "ioc_value": "81.71.159.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743349": [
        {
            "ioc_value": "83.229.123.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-10-11 09:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743350": [
        {
            "ioc_value": "83.229.126.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-10-11 09:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743348": [
        {
            "ioc_value": "8.153.205.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:14",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743347": [
        {
            "ioc_value": "8.137.149.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:13",
            "last_seen_utc": "2026-10-11 09:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743344": [
        {
            "ioc_value": "47.93.28.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743345": [
        {
            "ioc_value": "60.205.139.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-10-11 09:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743346": [
        {
            "ioc_value": "lcowpowerlite.italynorth.cloudapp.azure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-10-11 09:42:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743340": [
        {
            "ioc_value": "47.109.198.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-10-11 09:42:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743341": [
        {
            "ioc_value": "47.120.70.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743342": [
        {
            "ioc_value": "47.121.137.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743343": [
        {
            "ioc_value": "47.121.29.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-10-11 09:42:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743336": [
        {
            "ioc_value": "45.115.236.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743338": [
        {
            "ioc_value": "47.107.136.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743339": [
        {
            "ioc_value": "47.109.145.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743333": [
        {
            "ioc_value": "192.140.176.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-10-11 09:42:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743334": [
        {
            "ioc_value": "36.140.162.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-10-11 09:42:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743335": [
        {
            "ioc_value": "39.105.165.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743330": [
        {
            "ioc_value": "152.32.251.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743331": [
        {
            "ioc_value": "154.201.74.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743332": [
        {
            "ioc_value": "179.43.186.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-10-11 09:42:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743326": [
        {
            "ioc_value": "139.196.41.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743327": [
        {
            "ioc_value": "139.224.16.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743328": [
        {
            "ioc_value": "14.103.175.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743329": [
        {
            "ioc_value": "150.187.25.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-10-11 09:42:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743322": [
        {
            "ioc_value": "120.48.168.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743323": [
        {
            "ioc_value": "121.40.18.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743324": [
        {
            "ioc_value": "122.51.93.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743325": [
        {
            "ioc_value": "134.122.140.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743320": [
        {
            "ioc_value": "117.72.102.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743321": [
        {
            "ioc_value": "117.72.242.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743318": [
        {
            "ioc_value": "113.44.67.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743319": [
        {
            "ioc_value": "115.190.161.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743314": [
        {
            "ioc_value": "106.38.201.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-10-11 09:42:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743315": [
        {
            "ioc_value": "106.75.162.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-10-11 09:42:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743316": [
        {
            "ioc_value": "106.75.215.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743317": [
        {
            "ioc_value": "106.75.224.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743312": [
        {
            "ioc_value": "106.12.219.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-10-11 09:42:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743313": [
        {
            "ioc_value": "106.13.29.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-10-11 09:42:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743267": [
        {
            "ioc_value": "15.204.14.143:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 11:00:25",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.14.143",
            "tags": "AS16276,C2,censys,OVH",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1743209": [
        {
            "ioc_value": "15.204.95.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-02-08 04:00:55",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1742595": [
        {
            "ioc_value": "174.138.86.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-07 03:00:18",
            "last_seen_utc": "2026-10-11 09:44:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/174.138.86.141",
            "tags": "AS14061,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1742209": [
        {
            "ioc_value": "bravepolice.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-02-06 06:33:52",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix,validin",
            "anonymous": 0,
            "reporter": "DaveLikesMalwre"
        }
    ],
    "1741587": [
        {
            "ioc_value": "57.158.27.132:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-02-05 13:01:59",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/57.158.27.132#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1741451": [
        {
            "ioc_value": "139.84.159.182:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-02-05 08:00:33",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.84.159.182",
            "tags": "AS-VULTR,AS20473,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1741375": [
        {
            "ioc_value": "37.72.172.58:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:37",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS29802,asyncrat,c2,fofa,RAT",
            "anonymous": 0,
            "reporter": "oxygen28"
        }
    ],
    "1741222": [
        {
            "ioc_value": "3.121.234.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 15:54:23",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.121.234.29",
            "tags": "AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741132": [
        {
            "ioc_value": "172.174.234.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 11:00:54",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.174.234.34",
            "tags": "AS8075,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1740953": [
        {
            "ioc_value": "188.166.244.201:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-04 00:02:27",
            "last_seen_utc": "2026-10-11 09:44:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.166.244.201",
            "tags": "AdaptixC2,AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1740000": [
        {
            "ioc_value": "146.70.49.42:7080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-02 18:00:52",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260202-r1f9ysbx8f",
            "tags": "AS9009,asyncrat,C2,rat,triage",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739277": [
        {
            "ioc_value": "101.37.236.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-31 04:00:10",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.37.236.20",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-100000",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739209": [
        {
            "ioc_value": "47.115.193.52:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-01-30 18:54:11",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1739163": [
        {
            "ioc_value": "107.150.105.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 16:04:48",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.150.105.91",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739009": [
        {
            "ioc_value": "111.92.243.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 08:04:49",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.92.243.40",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1738855": [
        {
            "ioc_value": "209.145.63.3:33330",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-29 18:55:17",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1737790": [
        {
            "ioc_value": "47.120.46.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-26 23:00:09",
            "last_seen_utc": "2026-10-11 09:42:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.46.230",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1736034": [
        {
            "ioc_value": "158.158.8.193:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-01-23 08:45:57",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736014": [
        {
            "ioc_value": "47.120.32.72:8075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-23 08:04:06",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.32.72",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735921": [
        {
            "ioc_value": "104.243.248.63:103",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-23 00:04:39",
            "last_seen_utc": "2026-10-11 09:00:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.243.248.63",
            "tags": "AS3223,AsyncRAT,C2,censys,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735522": [
        {
            "ioc_value": "176.31.71.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 12:04:28",
            "last_seen_utc": "2026-10-11 09:44:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/176.31.71.168",
            "tags": "AS16276,C2,censys,OVH,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735412": [
        {
            "ioc_value": "34.64.98.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 04:04:19",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/34.64.98.201",
            "tags": "AS396982,C2,censys,GOOGLE-CLOUD-PLATFORM,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735387": [
        {
            "ioc_value": "34.64.98.201:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 00:04:16",
            "last_seen_utc": "2026-10-11 09:45:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/34.64.98.201",
            "tags": "AS396982,C2,censys,GOOGLE-CLOUD-PLATFORM,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735342": [
        {
            "ioc_value": "54.145.56.188:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-21 20:04:36",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.145.56.188",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734935": [
        {
            "ioc_value": "37.72.168.189:42334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-20 20:05:01",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.168.189",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734893": [
        {
            "ioc_value": "136.24.173.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-20 16:04:24",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/136.24.173.249",
            "tags": "AS19165,C2,censys,Mythic,WEBPASS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734787": [
        {
            "ioc_value": "104.243.248.63:83",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-20 08:04:17",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/104.243.248.63",
            "tags": "AS3223,AsyncRAT,C2,censys,RAT,VOXILITY",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734081": [
        {
            "ioc_value": "103.79.79.105:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-18 00:03:59",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.79.79.105",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1733911": [
        {
            "ioc_value": "qualitylivingpm.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-01-17 17:20:09",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "clickfix,validin",
            "anonymous": 0,
            "reporter": "DaveLikesMalwre"
        }
    ],
    "1733584": [
        {
            "ioc_value": "101.37.236.20:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 14:56:41",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1733583": [
        {
            "ioc_value": "test.dnslogger.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 14:56:19",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1732790": [
        {
            "ioc_value": "154.38.116.247:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-16 11:10:18",
            "last_seen_utc": "2026-10-11 09:43:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/154.38.116.247#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1732712": [
        {
            "ioc_value": "111.231.116.164:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 11:03:49",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.231.116.164#4443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1731532": [
        {
            "ioc_value": "54.38.94.225:8881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-01-13 08:52:00",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1693365": [
        {
            "ioc_value": "117.72.178.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 23:00:12",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.178.246",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693357": [
        {
            "ioc_value": "172.94.18.103:191",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-08 22:50:04",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1693228": [
        {
            "ioc_value": "39.107.242.130:52012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 11:00:08",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.107.242.130",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693090": [
        {
            "ioc_value": "123.249.100.226:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 08:51:57",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1692743": [
        {
            "ioc_value": "38.49.57.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-07 20:02:36",
            "last_seen_utc": "2026-10-11 09:42:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.49.57.15",
            "tags": "AS8796,C2,censys,CobaltStrike,cs-watermark-666666666,FD-298-8796",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691952": [
        {
            "ioc_value": "115.190.233.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-06 08:02:23",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.233.79",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691605": [
        {
            "ioc_value": "http://213.5.130.122",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:42",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691603": [
        {
            "ioc_value": "http://213.5.130.151",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:41",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691604": [
        {
            "ioc_value": "http://213.5.130.124",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691606": [
        {
            "ioc_value": "http://213.5.130.187",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-10-10 18:01:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1690200": [
        {
            "ioc_value": "jairosorio.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-01-02 19:05:57",
            "last_seen_utc": "2026-10-09 16:19:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "clickfix,validin",
            "anonymous": 0,
            "reporter": "DaveLikesMalwre"
        }
    ],
    "1690055": [
        {
            "ioc_value": "dekwatlaos.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-01-02 19:05:47",
            "last_seen_utc": "2026-10-09 16:19:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "clickfix,validin",
            "anonymous": 0,
            "reporter": "DaveLikesMalwre"
        }
    ],
    "1689911": [
        {
            "ioc_value": "ajkerbarta.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-01-02 19:05:36",
            "last_seen_utc": "2026-10-09 16:19:43",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "clickfix,validin",
            "anonymous": 0,
            "reporter": "DaveLikesMalwre"
        }
    ],
    "1688739": [
        {
            "ioc_value": "101.34.205.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:16",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688738": [
        {
            "ioc_value": "103.171.35.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:15",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688737": [
        {
            "ioc_value": "107.149.192.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:14",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688734": [
        {
            "ioc_value": "124.222.218.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688735": [
        {
            "ioc_value": "124.221.255.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688736": [
        {
            "ioc_value": "123.56.78.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688732": [
        {
            "ioc_value": "152.32.202.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688733": [
        {
            "ioc_value": "150.158.119.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688730": [
        {
            "ioc_value": "165.154.244.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688731": [
        {
            "ioc_value": "156.225.20.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688729": [
        {
            "ioc_value": "182.92.239.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:10",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688726": [
        {
            "ioc_value": "39.105.160.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688727": [
        {
            "ioc_value": "38.38.250.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688728": [
        {
            "ioc_value": "211.184.175.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688725": [
        {
            "ioc_value": "45.58.56.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:07",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688723": [
        {
            "ioc_value": "8.130.80.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688724": [
        {
            "ioc_value": "8.130.26.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688721": [
        {
            "ioc_value": "94.74.164.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688722": [
        {
            "ioc_value": "87.251.67.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688694": [
        {
            "ioc_value": "16.171.13.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-30 16:04:05",
            "last_seen_utc": "2026-10-11 09:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/16.171.13.191",
            "tags": "AMAZON-02,AS16509,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1687948": [
        {
            "ioc_value": "222.186.17.103:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-29 08:46:57",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687817": [
        {
            "ioc_value": "118.89.88.183:56781",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-28 20:01:34",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.89.88.183",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1687807": [
        {
            "ioc_value": "163.181.213.114:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-28 18:44:20",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687327": [
        {
            "ioc_value": "37.72.172.58:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-28 07:41:32",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1687170": [
        {
            "ioc_value": "37.72.172.58:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-27 16:02:33",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1686405": [
        {
            "ioc_value": "155.102.62.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-25 18:44:15",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1686010": [
        {
            "ioc_value": "139.196.223.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-25 07:52:31",
            "last_seen_utc": "2026-10-11 09:42:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.196.223.82",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1685856": [
        {
            "ioc_value": "helpremote.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-24 12:48:51",
            "last_seen_utc": "2026-10-11 09:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685596": [
        {
            "ioc_value": "172.94.18.103:190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 22:45:05",
            "last_seen_utc": "2026-10-11 09:44:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685256": [
        {
            "ioc_value": "115.190.160.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 20:01:06",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.160.206",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1684938": [
        {
            "ioc_value": "8.159.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 03:00:34",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684936": [
        {
            "ioc_value": "missmovie.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 02:54:49",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684826": [
        {
            "ioc_value": "179.43.186.214:7889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 20:01:00",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/179.43.186.214",
            "tags": "AS51852,C2,censys,CobaltStrike,cs-watermark-987654321,PLI-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1682522": [
        {
            "ioc_value": "155.102.133.61:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-18 18:44:36",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1680395": [
        {
            "ioc_value": "119.45.160.160:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 06:49:03",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.45.160.160#8889",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1676363": [
        {
            "ioc_value": "67.219.102.244:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-12 02:50:28",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1671125": [
        {
            "ioc_value": "amenom.jp",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2025-12-08 19:00:07",
            "last_seen_utc": "2026-10-10 09:11:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,Clickfix",
            "anonymous": 0,
            "reporter": "DaveLikesMalwre"
        }
    ],
    "1670887": [
        {
            "ioc_value": "20.157.116.151:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-08 14:58:40",
            "last_seen_utc": "2026-10-11 09:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.157.116.151",
            "tags": "AdaptixC2,AS8069,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1668967": [
        {
            "ioc_value": "180.76.141.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-07 16:01:37",
            "last_seen_utc": "2026-10-11 09:46:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.141.175",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667706": [
        {
            "ioc_value": "84.32.5.105:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-12-04 16:02:10",
            "last_seen_utc": "2026-10-11 05:38:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/84.32.5.105",
            "tags": "AS62164,C2,censys,HEYMMAN-2,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667105": [
        {
            "ioc_value": "115.190.161.178:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-03 20:01:15",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.161.178",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1665523": [
        {
            "ioc_value": "http://213.5.130.104",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665524": [
        {
            "ioc_value": "http://213.5.130.180",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665525": [
        {
            "ioc_value": "http://213.5.130.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:50",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665527": [
        {
            "ioc_value": "http://213.5.130.152",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665528": [
        {
            "ioc_value": "http://213.5.130.107",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665529": [
        {
            "ioc_value": "http://213.5.130.153",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665530": [
        {
            "ioc_value": "http://213.5.130.100",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665531": [
        {
            "ioc_value": "http://213.5.130.182",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1663012": [
        {
            "ioc_value": "47.236.56.15:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 12:00:52",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.56.15",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1651463": [
        {
            "ioc_value": "172.94.15.100:6075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-11-27 06:58:30",
            "last_seen_utc": "2026-10-10 19:58:46",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1650889": [
        {
            "ioc_value": "job.itechno.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-26 12:50:54",
            "last_seen_utc": "2026-10-10 10:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1650040": [
        {
            "ioc_value": "156.245.248.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-25 10:49:55",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1649775": [
        {
            "ioc_value": "http://213.5.130.84",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:37",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649776": [
        {
            "ioc_value": "http://213.5.130.96",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-10-11 06:01:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649777": [
        {
            "ioc_value": "http://213.5.130.98",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649778": [
        {
            "ioc_value": "http://213.5.130.160",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:35",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1646839": [
        {
            "ioc_value": "43.156.63.124:64494",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-19 23:00:16",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.156.63.124",
            "tags": "AS132203,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1645785": [
        {
            "ioc_value": "47.236.149.142:46832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-17 23:00:18",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.149.142",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1645519": [
        {
            "ioc_value": "http://185.132.133.127",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1645520": [
        {
            "ioc_value": "http://185.132.133.140",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1641688": [
        {
            "ioc_value": "117.72.209.125:18888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 16:43:15",
            "last_seen_utc": "2026-10-11 09:19:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS141679,China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch,supershell",
            "anonymous": 0,
            "reporter": "antiphishorg"
        }
    ],
    "1641582": [
        {
            "ioc_value": "62.4.0.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 08:48:18",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1639703": [
        {
            "ioc_value": "62.60.226.183:483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2025-11-13 04:54:17",
            "last_seen_utc": "2026-10-11 09:00:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Tofsee",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1639434": [
        {
            "ioc_value": "62.4.0.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 16:02:00",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.4.0.66",
            "tags": "AS12876,C2,censys,Mythic,Online",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1639246": [
        {
            "ioc_value": "rx.fabiankorte.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-11-12 09:18:59",
            "last_seen_utc": "2026-10-10 06:27:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1639229": [
        {
            "ioc_value": "https://rx.fabiankorte.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-11-12 09:18:14",
            "last_seen_utc": "2026-10-10 06:27:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1638854": [
        {
            "ioc_value": "54.165.230.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 04:02:31",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.165.230.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638662": [
        {
            "ioc_value": "208.87.129.112:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-11 12:01:51",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/208.87.129.112",
            "tags": "AS29802,C2,censys,HVC-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638250": [
        {
            "ioc_value": "124.221.237.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-10 16:51:33",
            "last_seen_utc": "2026-10-11 09:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1638236": [
        {
            "ioc_value": "154.205.145.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-11-10 16:02:55",
            "last_seen_utc": "2026-10-10 18:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.205.145.109",
            "tags": "AS138915,C2,censys,Havoc,KAOPU-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1636099": [
        {
            "ioc_value": "111.228.55.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 23:00:12",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.228.55.96",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1634744": [
        {
            "ioc_value": "165.154.225.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 02:49:37",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1634389": [
        {
            "ioc_value": "139.196.111.118:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-06 07:26:25",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633501": [
        {
            "ioc_value": "59.110.28.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 20:01:04",
            "last_seen_utc": "2026-10-11 09:42:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/59.110.28.230",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633194": [
        {
            "ioc_value": "51.15.8.6:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-04 08:00:54",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.8.6",
            "tags": "AS12876,C2,censys,Online,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633063": [
        {
            "ioc_value": "192.253.227.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:22",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633061": [
        {
            "ioc_value": "167.88.168.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:14",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1631753": [
        {
            "ioc_value": "117.72.175.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2025-11-03 12:08:57",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.nviso.eu/blog",
            "tags": "C2,NVISO,VShell",
            "anonymous": 0,
            "reporter": "0xThiebaut"
        }
    ],
    "1631367": [
        {
            "ioc_value": "117.72.242.9:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 09:03:04",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.242.9",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1631471": [
        {
            "ioc_value": "119.42.148.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 07:01:12",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.42.148.186#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630266": [
        {
            "ioc_value": "116.62.34.159:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-31 10:49:36",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1629384": [
        {
            "ioc_value": "103.149.93.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-30 04:00:42",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.149.93.146",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1628814": [
        {
            "ioc_value": "179.43.186.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 09:23:45",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627925": [
        {
            "ioc_value": "182.254.155.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 04:00:27",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/182.254.155.23",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1627719": [
        {
            "ioc_value": "182.16.98.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 02:49:21",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627659": [
        {
            "ioc_value": "182.16.98.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-27 20:50:01",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1626705": [
        {
            "ioc_value": "196.251.83.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:39:14",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/196.251.83.89",
            "tags": "AS401120,C2,censys,CHEAPY-HOST",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1626300": [
        {
            "ioc_value": "47.121.135.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-25 04:00:11",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.121.135.201",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626112": [
        {
            "ioc_value": "140.143.194.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-24 16:00:08",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/140.143.194.253",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1625642": [
        {
            "ioc_value": "maelootp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 16:48:58",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625564": [
        {
            "ioc_value": "evil.ritademo.io.vn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 12:50:22",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1624905": [
        {
            "ioc_value": "116.62.226.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 15:43:44",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1624300": [
        {
            "ioc_value": "47.110.67.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 20:01:59",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.110.67.64",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1624166": [
        {
            "ioc_value": "http://213.5.130.75",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:24",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624167": [
        {
            "ioc_value": "http://213.5.130.10",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:23",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624169": [
        {
            "ioc_value": "http://213.5.130.90",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624170": [
        {
            "ioc_value": "http://213.5.130.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-10-11 06:01:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1618876": [
        {
            "ioc_value": "www.salesf0rce.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:37",
            "last_seen_utc": "2026-10-11 09:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1616729": [
        {
            "ioc_value": "47.129.2.130:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:50:54",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1616728": [
        {
            "ioc_value": "ns1.gygiuh.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:49:04",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1615761": [
        {
            "ioc_value": "89.58.30.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-14 20:02:48",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.58.30.49",
            "tags": "AS197540,C2,censys,Covenant,NETCUP-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1608604": [
        {
            "ioc_value": "114.132.248.120:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-07 02:48:54",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1604499": [
        {
            "ioc_value": "149.50.135.215:49152",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-30 00:02:15",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.50.135.215",
            "tags": "AdaptixC2,AS27823,C2,censys,Dattatec.com",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1603281": [
        {
            "ioc_value": "154.92.15.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-28 15:48:32",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1601556": [
        {
            "ioc_value": "115.120.245.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 20:00:39",
            "last_seen_utc": "2026-10-11 09:42:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.120.245.134",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1601359": [
        {
            "ioc_value": "196.251.69.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 12:51:01",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1599651": [
        {
            "ioc_value": "47.113.186.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 20:00:10",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.113.186.138",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599442": [
        {
            "ioc_value": "43.162.114.240:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-24 08:02:13",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.240",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599090": [
        {
            "ioc_value": "46.21.153.148:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-23 20:01:59",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.21.153.148",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599091": [
        {
            "ioc_value": "46.21.153.146:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-23 20:01:59",
            "last_seen_utc": "2026-10-11 09:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.21.153.146",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1598300": [
        {
            "ioc_value": "43.162.114.107:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-23 04:00:59",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.107",
            "tags": "AS132203,censys,EvilGinx,Phishing",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1598102": [
        {
            "ioc_value": "159.75.211.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:51:05",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1598100": [
        {
            "ioc_value": "cstest.mucfc.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:49:30",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597898": [
        {
            "ioc_value": "ns2.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:38",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597894": [
        {
            "ioc_value": "ns1.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:35",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1596535": [
        {
            "ioc_value": "43.162.108.133:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-21 16:01:22",
            "last_seen_utc": "2026-10-11 09:45:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.108.133",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1595224": [
        {
            "ioc_value": "146.70.79.45:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-09-18 20:02:44",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.79.45",
            "tags": "AS9009,C2,censys,M247,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1589068": [
        {
            "ioc_value": "18.167.174.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-09-13 04:01:58",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.167.174.198",
            "tags": "AMAZON-02,AS16509,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588133": [
        {
            "ioc_value": "195.178.110.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:36",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.178.110.135",
            "tags": "AS48090,C2,censys,CobaltStrike,cs-watermark-426352781,DMZHOST",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588128": [
        {
            "ioc_value": "150.158.170.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:30",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.158.170.241",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1587773": [
        {
            "ioc_value": "106.12.111.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 06:43:14",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1587441": [
        {
            "ioc_value": "101.32.109.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-10 20:01:24",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.32.109.112",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1582910": [
        {
            "ioc_value": "8.138.222.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-06 20:01:18",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.222.215",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1581557": [
        {
            "ioc_value": "8.148.194.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-04 07:40:17",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.148.194.157#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580723": [
        {
            "ioc_value": "47.236.159.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:52:55",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580721": [
        {
            "ioc_value": "ns2.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:45",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580720": [
        {
            "ioc_value": "ns1.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:42",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580237": [
        {
            "ioc_value": "47.99.196.178:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-02 04:01:38",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.99.196.178",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578921": [
        {
            "ioc_value": "109.205.181.248:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-01 00:01:11",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578899": [
        {
            "ioc_value": "103.73.66.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-31 20:50:07",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1578379": [
        {
            "ioc_value": "109.205.181.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-31 04:00:27",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1577938": [
        {
            "ioc_value": "178.16.52.221:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-08-30 08:00:39",
            "last_seen_utc": "2026-10-11 09:29:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.52.221",
            "tags": "AS209800,C2,censys,METASPINNER-ASN,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1577783": [
        {
            "ioc_value": "43.199.78.142:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:50:45",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577775": [
        {
            "ioc_value": "n1.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577776": [
        {
            "ioc_value": "n2.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577777": [
        {
            "ioc_value": "n3.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577774": [
        {
            "ioc_value": "lab.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:01",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1573705": [
        {
            "ioc_value": "43.163.112.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 00:00:27",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.163.112.217",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1572897": [
        {
            "ioc_value": "pensi.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-23 04:00:06",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/217.154.212.25+pensi.me",
            "tags": "AS8560,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1572377": [
        {
            "ioc_value": "89.208.211.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-21 20:00:56",
            "last_seen_utc": "2026-10-11 09:45:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.208.211.30",
            "tags": "AS47764,C2,censys,Mythic,VK-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1571607": [
        {
            "ioc_value": "178.16.55.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-20 08:02:12",
            "last_seen_utc": "2026-10-11 09:42:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.55.53",
            "tags": "C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1571152": [
        {
            "ioc_value": "46.246.14.5:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-08-19 05:50:06",
            "last_seen_utc": "2026-10-11 09:45:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1570775": [
        {
            "ioc_value": "116.203.31.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-18 20:01:59",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.203.31.207",
            "tags": "AS24940,C2,censys,CobaltStrike,cs-watermark-987654321,HETZNER-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570558": [
        {
            "ioc_value": "150.187.25.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-17 20:01:54",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.187.25.242",
            "tags": "AS20312,C2,censys,CobaltStrike,cs-watermark-987654321,Fundacion",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569825": [
        {
            "ioc_value": "8.138.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 15:22:26",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.138.167.123#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1569780": [
        {
            "ioc_value": "119.29.231.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:01:47",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.29.231.118",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569167": [
        {
            "ioc_value": "116.198.233.179:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 21:57:45",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.198.233.179#6666",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1568713": [
        {
            "ioc_value": "117.72.184.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 06:21:34",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.184.172",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1567756": [
        {
            "ioc_value": "116.198.233.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 20:01:25",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.198.233.179",
            "tags": "AS137699,C2,censys,CHINATELECOM-JIANGSU-SUQIAN-IDC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567668": [
        {
            "ioc_value": "62.117.98.115:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-12 12:01:59",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.117.98.115",
            "tags": "AS8732,C2,censys,COMCOR-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567648": [
        {
            "ioc_value": "107.174.115.43:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 10:50:19",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567336": [
        {
            "ioc_value": "150.158.119.242:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 22:50:14",
            "last_seen_utc": "2026-10-11 09:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567334": [
        {
            "ioc_value": "hibmarket.help",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 22:49:05",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567316": [
        {
            "ioc_value": "209.250.227.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-08-11 20:01:43",
            "last_seen_utc": "2026-10-11 09:44:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/209.250.227.127",
            "tags": "AS-VULTR,AS20473,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567234": [
        {
            "ioc_value": "45.204.216.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 08:01:15",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.204.216.24",
            "tags": "AS62468,C2,censys,CobaltStrike,cs-watermark-987654321,HKCLOUDX",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1565164": [
        {
            "ioc_value": "8.219.76.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:54:26",
            "last_seen_utc": "2026-10-11 09:42:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564496": [
        {
            "ioc_value": "47.105.36.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 08:53:36",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1563212": [
        {
            "ioc_value": "194.87.82.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-01 20:01:06",
            "last_seen_utc": "2026-10-11 09:44:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/194.87.82.8",
            "tags": "AS26383,ASNET,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1562605": [
        {
            "ioc_value": "172.233.97.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-30 20:01:06",
            "last_seen_utc": "2026-10-11 09:43:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.233.97.159",
            "tags": "AKAMAI-LINODE-AP,AS63949,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1561181": [
        {
            "ioc_value": "117.72.181.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-27 16:00:55",
            "last_seen_utc": "2026-10-11 09:46:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.181.104",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1560617": [
        {
            "ioc_value": "47.236.130.154:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-25 10:51:18",
            "last_seen_utc": "2026-10-11 09:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558329": [
        {
            "ioc_value": "103.125.248.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-19 12:49:30",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558066": [
        {
            "ioc_value": "193.112.84.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-18 12:51:20",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557619": [
        {
            "ioc_value": "ns3.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:04",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557618": [
        {
            "ioc_value": "ns2.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:03",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557617": [
        {
            "ioc_value": "ns1.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:02",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1556099": [
        {
            "ioc_value": "51.81.171.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-07-12 00:01:36",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1555968": [
        {
            "ioc_value": "175.178.77.207:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-11 12:53:20",
            "last_seen_utc": "2026-10-11 09:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1554340": [
        {
            "ioc_value": "88.129.147.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-07 20:54:20",
            "last_seen_utc": "2026-10-11 09:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1554064": [
        {
            "ioc_value": "8.152.99.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-06 20:00:32",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.152.99.85",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1552741": [
        {
            "ioc_value": "43.139.59.122:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-02 13:17:50",
            "last_seen_utc": "2026-10-11 09:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1552208": [
        {
            "ioc_value": "146.70.87.96:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-02 04:02:12",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.87.96",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1551843": [
        {
            "ioc_value": "38.132.122.141:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-01 04:02:16",
            "last_seen_utc": "2026-10-11 09:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.132.122.141",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1551795": [
        {
            "ioc_value": "146.70.87.237:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-01 00:02:11",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.87.237",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1551534": [
        {
            "ioc_value": "https://17.aa.4t.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-06-30 07:56:18",
            "last_seen_utc": "2026-10-10 06:31:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "jaa3n,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1551535": [
        {
            "ioc_value": "17.aa.4t.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-06-30 07:56:18",
            "last_seen_utc": "2026-10-10 06:31:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "jaa3n,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550784": [
        {
            "ioc_value": "116.205.143.204:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:54:22",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550783": [
        {
            "ioc_value": "dns1.globalcdn.autos",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:53:12",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1550284": [
        {
            "ioc_value": "54.38.94.225:8886",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-28 08:51:18",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1549426": [
        {
            "ioc_value": "217.154.212.25:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-26 13:03:23",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/217.154.212.25#8443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1549030": [
        {
            "ioc_value": "156.227.233.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-25 04:00:19",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.227.233.153",
            "tags": "AS138152,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1548628": [
        {
            "ioc_value": "102.117.168.208:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-23 12:02:20",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/102.117.168.208",
            "tags": "AS23889,C2,censys,MauritiusTelecom,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1548104": [
        {
            "ioc_value": "158.158.0.196:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-20 20:02:50",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1547925": [
        {
            "ioc_value": "82.156.156.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-20 06:01:32",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1546420": [
        {
            "ioc_value": "158.158.0.196:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-19 00:02:44",
            "last_seen_utc": "2026-10-11 09:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1545615": [
        {
            "ioc_value": "8.147.128.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-17 03:12:25",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545575": [
        {
            "ioc_value": "38.132.122.145:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-16 20:02:54",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.132.122.145",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1545236": [
        {
            "ioc_value": "23.227.199.61:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-16 08:02:52",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.199.61",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544669": [
        {
            "ioc_value": "23.227.203.246:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-14 04:02:35",
            "last_seen_utc": "2026-10-11 09:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.203.246",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544612": [
        {
            "ioc_value": "47.109.48.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-13 20:01:30",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.48.57",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544039": [
        {
            "ioc_value": "39.104.78.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-12 08:56:19",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.104.78.25",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1543390": [
        {
            "ioc_value": "8.155.0.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-10 16:01:13",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.155.0.238",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1543182": [
        {
            "ioc_value": "23.227.203.190:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-10 00:02:13",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.203.190",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542809": [
        {
            "ioc_value": "38.132.122.161:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-08 21:18:40",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.132.122.161",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542806": [
        {
            "ioc_value": "146.70.87.64:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-08 21:18:39",
            "last_seen_utc": "2026-10-11 09:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.87.64",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542802": [
        {
            "ioc_value": "23.227.203.128:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-08 21:18:37",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.203.128",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542804": [
        {
            "ioc_value": "23.227.203.191:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-08 21:18:37",
            "last_seen_utc": "2026-10-11 09:45:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.203.191",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542784": [
        {
            "ioc_value": "162.248.224.223:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-06-08 20:45:49",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1542783": [
        {
            "ioc_value": "162.248.224.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-06-08 20:45:48",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1542759": [
        {
            "ioc_value": "119.45.29.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-08 20:01:01",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.45.29.172",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1541652": [
        {
            "ioc_value": "68.64.176.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 16:00:50",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.176.42",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-391144938,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1541500": [
        {
            "ioc_value": "gou.xiaogoubi.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 06:17:59",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,cobaltstrike",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1538881": [
        {
            "ioc_value": "193.239.85.15:2083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-06-02 12:01:04",
            "last_seen_utc": "2026-10-11 09:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.239.85.15",
            "tags": "AS9009,C2,censys,Havoc,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1538799": [
        {
            "ioc_value": "47.109.198.8:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-02 05:47:28",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.109.198.8#6000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1538358": [
        {
            "ioc_value": "54.38.94.225:8885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-01 08:52:56",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1537676": [
        {
            "ioc_value": "101.43.91.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:39",
            "last_seen_utc": "2026-10-11 09:42:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1537678": [
        {
            "ioc_value": "59.110.7.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:38",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1536850": [
        {
            "ioc_value": "99.112.198.249:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-05-30 08:53:21",
            "last_seen_utc": "2026-10-11 09:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536831": [
        {
            "ioc_value": "129.28.85.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 08:00:11",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/129.28.85.210",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1536730": [
        {
            "ioc_value": "111.229.4.108:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 02:55:17",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536683": [
        {
            "ioc_value": "161.35.176.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-29 22:26:34",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.176.231",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1535962": [
        {
            "ioc_value": "217.154.212.25:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-28 08:01:49",
            "last_seen_utc": "2026-10-11 09:46:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/217.154.212.25",
            "tags": "AS8560,C2,censys,IONOS-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1535294": [
        {
            "ioc_value": "101.37.236.20:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-27 16:54:47",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.37.236.20#1111",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1534703": [
        {
            "ioc_value": "38.54.23.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-05-26 06:29:51",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.54.23.241",
            "tags": "AS138915,C2,censys,KAOPU-HK,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533613": [
        {
            "ioc_value": "221.132.29.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-24 20:01:31",
            "last_seen_utc": "2026-10-11 09:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/221.132.29.137",
            "tags": "AS45899,C2,censys,Mythic,VNPT-AS-VN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533071": [
        {
            "ioc_value": "1.15.174.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-24 11:13:44",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1532332": [
        {
            "ioc_value": "8.140.239.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-23 05:34:51",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1532168": [
        {
            "ioc_value": "159.75.146.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-22 12:58:28",
            "last_seen_utc": "2026-10-11 09:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1527752": [
        {
            "ioc_value": "117.72.206.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 08:00:35",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.206.39",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1526357": [
        {
            "ioc_value": "106.54.61.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-20 06:37:42",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1525250": [
        {
            "ioc_value": "124.223.114.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-18 15:34:22",
            "last_seen_utc": "2026-10-11 09:42:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://intelinsights.substack.com/p/from-939-to-85-hunting-cobalt-strike",
            "tags": "censys,cobaltstrike",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1524773": [
        {
            "ioc_value": "167.99.51.2:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 14:42:08",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.99.51.2#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1524641": [
        {
            "ioc_value": "167.99.51.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 08:00:32",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.51.2",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1524319": [
        {
            "ioc_value": "101.35.109.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-17 06:26:23",
            "last_seen_utc": "2026-10-11 09:42:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.35.109.246#443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1523466": [
        {
            "ioc_value": "103.171.35.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:57",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523462": [
        {
            "ioc_value": "60.204.169.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:47",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523434": [
        {
            "ioc_value": "179.43.186.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:13:56",
            "last_seen_utc": "2026-10-11 09:42:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523280": [
        {
            "ioc_value": "45.133.180.138:6432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-05-15 06:10:52",
            "last_seen_utc": "2026-10-11 09:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b6185d4054c5a08141db4c3fb5e43369ea21af5892d8ba47628e23f37f79250d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520343": [
        {
            "ioc_value": "38.54.112.234:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:58:42",
            "last_seen_utc": "2026-10-11 09:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520342": [
        {
            "ioc_value": "asusupdateserver.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:55:40",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1518023": [
        {
            "ioc_value": "106.52.207.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-07 13:00:19",
            "last_seen_utc": "2026-10-11 09:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1516140": [
        {
            "ioc_value": "107.173.4.16:2561",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-05-05 12:00:30",
            "last_seen_utc": "2026-10-11 07:39:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.173.4.16",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1513590": [
        {
            "ioc_value": "54.38.94.225:8882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-04-29 08:53:29",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513585": [
        {
            "ioc_value": "107.143.144.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-04-29 08:43:42",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1510881": [
        {
            "ioc_value": "20.89.67.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-24 08:00:55",
            "last_seen_utc": "2026-10-11 09:44:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.89.67.216",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1510481": [
        {
            "ioc_value": "114.132.180.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-23 12:58:59",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1509966": [
        {
            "ioc_value": "167.71.13.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-22 12:21:47",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.71.13.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1493521": [
        {
            "ioc_value": "77.73.129.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-04-18 08:02:32",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.73.129.82",
            "tags": "AS201814,C2,censys,MEVSPACE,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492480": [
        {
            "ioc_value": "113.45.253.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 16:01:35",
            "last_seen_utc": "2026-10-11 09:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.253.80",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-666666666,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492012": [
        {
            "ioc_value": "47.83.134.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-15 16:02:30",
            "last_seen_utc": "2026-10-11 09:45:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.83.134.97",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1486723": [
        {
            "ioc_value": "https://rofleratom.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-04-10 14:38:58",
            "last_seen_utc": "2026-10-11 09:44:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Latrodectus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1486437": [
        {
            "ioc_value": "167.71.13.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-10 05:55:49",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.71.13.103",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1466254": [
        {
            "ioc_value": "138671f56898c4504a02588c6f9c4de6a3961ce015bb147d579bd54bc454ded1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.lumma",
            "malware_alias": "LummaC2 Stealer",
            "malware_printable": "Lumma Stealer",
            "first_seen_utc": "2025-04-02 14:22:46",
            "last_seen_utc": "2026-10-09 15:46:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/IOC/blob/main/Lumma%20Stealer",
            "tags": "infostealer,lumma,lummastealer,stealer",
            "anonymous": 0,
            "reporter": "TheRavenFile"
        }
    ],
    "1463173": [
        {
            "ioc_value": "38.46.218.36:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:14",
            "last_seen_utc": "2026-10-11 07:07:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463174": [
        {
            "ioc_value": "38.46.218.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:13",
            "last_seen_utc": "2026-10-11 08:11:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463176": [
        {
            "ioc_value": "38.46.218.39:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:12",
            "last_seen_utc": "2026-10-11 09:43:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1462468": [
        {
            "ioc_value": "43.143.229.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-01 10:24:30",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1458716": [
        {
            "ioc_value": "ehchq7m7rpvdr.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-25 22:53:24",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1457513": [
        {
            "ioc_value": "103.142.147.17:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-24 06:29:33",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.142.147.17",
            "tags": "AS135581,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1452404": [
        {
            "ioc_value": "47.116.208.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-20 12:01:27",
            "last_seen_utc": "2026-10-11 09:42:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.208.81",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1446559": [
        {
            "ioc_value": "www.dyshop.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-12 02:47:28",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1441769": [
        {
            "ioc_value": "51.81.171.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-06 04:01:35",
            "last_seen_utc": "2026-10-11 09:45:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.81.171.234",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1440087": [
        {
            "ioc_value": "15.204.95.228:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-03-03 12:01:16",
            "last_seen_utc": "2026-10-11 09:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/15.204.95.228",
            "tags": "AS16276,C2,censys,Havoc,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439368": [
        {
            "ioc_value": "54.38.94.225:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-03-02 08:46:23",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439168": [
        {
            "ioc_value": "47.129.171.26:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:47:46",
            "last_seen_utc": "2026-10-11 09:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439166": [
        {
            "ioc_value": "ns.1.3.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439167": [
        {
            "ioc_value": "ns.1.4.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1424023": [
        {
            "ioc_value": "103.215.216.174:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-02-19 16:00:59",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.215.216.174",
            "tags": "AS202422,C2,censys,GHOST,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1414853": [
        {
            "ioc_value": "54.95.208.190:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-02-19 04:01:34",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.95.208.190",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1409420": [
        {
            "ioc_value": "103.215.81.156:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-10 20:43:10",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1404178": [
        {
            "ioc_value": "20.74.209.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-05 22:51:06",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402480": [
        {
            "ioc_value": "service-rchqbzvz-1301033415.sh.tencentapigw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-02 12:49:35",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1398820": [
        {
            "ioc_value": "162.252.173.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 13:44:30",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1398810": [
        {
            "ioc_value": "162.252.173.12:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 12:01:38",
            "last_seen_utc": "2026-10-11 09:43:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/162.252.173.12",
            "tags": "AS9009,backdoor,C2,censys,M247,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1396136": [
        {
            "ioc_value": "38.146.28.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:47:19",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396135": [
        {
            "ioc_value": "185.33.86.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:45:48",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396130": [
        {
            "ioc_value": "38.146.28.93:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:38",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.146.28.93",
            "tags": "AS174,backdoor,C2,censys,COGENT-174,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1396102": [
        {
            "ioc_value": "185.33.86.15:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 04:01:31",
            "last_seen_utc": "2026-10-11 09:44:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.33.86.15",
            "tags": "AS202015,backdoor,C2,censys,HZ-US-AS,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1394408": [
        {
            "ioc_value": "54.38.94.225:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-26 08:46:00",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1394158": [
        {
            "ioc_value": "54.38.94.225:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-25 20:47:04",
            "last_seen_utc": "2026-10-11 09:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384920": [
        {
            "ioc_value": "167.99.139.231:8003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384921": [
        {
            "ioc_value": "167.99.139.231:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-10-11 09:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384912": [
        {
            "ioc_value": "185.174.101.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384913": [
        {
            "ioc_value": "185.174.101.240:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384914": [
        {
            "ioc_value": "185.174.101.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384915": [
        {
            "ioc_value": "185.174.101.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-10-11 09:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384910": [
        {
            "ioc_value": "108.181.182.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384911": [
        {
            "ioc_value": "108.181.182.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384790": [
        {
            "ioc_value": "at1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384791": [
        {
            "ioc_value": "at2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384792": [
        {
            "ioc_value": "at3.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-10-11 09:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384322": [
        {
            "ioc_value": "152.42.180.208:8875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-16 04:03:31",
            "last_seen_utc": "2026-10-10 07:54:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/152.42.180.208",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Supershell",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1383107": [
        {
            "ioc_value": "194.180.48.18:45265",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-01-13 19:38:30",
            "last_seen_utc": "2026-10-11 08:28:04",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,remcos",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1381420": [
        {
            "ioc_value": "77.238.236.123:18300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:55:47",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1381067": [
        {
            "ioc_value": "112.5.58.181:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:43:51",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380875": [
        {
            "ioc_value": "update.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380878": [
        {
            "ioc_value": "upgrade.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380837": [
        {
            "ioc_value": "ns3.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380818": [
        {
            "ioc_value": "ns2.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:27",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380815": [
        {
            "ioc_value": "ns2.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:26",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380783": [
        {
            "ioc_value": "ns1.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380787": [
        {
            "ioc_value": "ns1.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-10-11 09:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380635": [
        {
            "ioc_value": "8.219.78.159:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:57",
            "last_seen_utc": "2026-10-11 09:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380629": [
        {
            "ioc_value": "70.34.196.238:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:43",
            "last_seen_utc": "2026-10-11 09:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380607": [
        {
            "ioc_value": "47.98.134.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:28",
            "last_seen_utc": "2026-10-11 09:42:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380446": [
        {
            "ioc_value": "139.180.189.95:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:16:21",
            "last_seen_utc": "2026-10-11 09:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380421": [
        {
            "ioc_value": "118.25.91.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:44",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1359401": [
        {
            "ioc_value": "8.153.97.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-24 08:00:43",
            "last_seen_utc": "2026-10-11 09:42:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.153.97.202",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359309": [
        {
            "ioc_value": "91.199.154.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-12-24 04:01:34",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "AS62212,C2,censys,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359295": [
        {
            "ioc_value": "54.95.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-12-24 00:02:17",
            "last_seen_utc": "2026-10-11 09:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.95.208.190",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1358903": [
        {
            "ioc_value": "111.170.148.134:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-21 07:32:55",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.170.148.134",
            "tags": "AS4134,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1358842": [
        {
            "ioc_value": "149.28.61.158:8773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-20 16:01:53",
            "last_seen_utc": "2026-10-11 09:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.61.158",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1358518": [
        {
            "ioc_value": "102.117.162.232:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-19 12:01:50",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/102.117.162.232",
            "tags": "AS23889,C2,censys,MauritiusTelecom,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1352876": [
        {
            "ioc_value": "139.196.126.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-06 07:36:52",
            "last_seen_utc": "2026-10-11 09:42:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1349567": [
        {
            "ioc_value": "216.118.101.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:19",
            "last_seen_utc": "2026-10-11 09:44:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349531": [
        {
            "ioc_value": "216.118.101.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:11",
            "last_seen_utc": "2026-10-11 09:44:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349510": [
        {
            "ioc_value": "216.118.101.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:08",
            "last_seen_utc": "2026-10-11 09:44:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349492": [
        {
            "ioc_value": "216.118.101.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:04",
            "last_seen_utc": "2026-10-11 09:44:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349445": [
        {
            "ioc_value": "113.44.89.87:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:53",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349438": [
        {
            "ioc_value": "216.118.101.54:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:51",
            "last_seen_utc": "2026-10-11 09:44:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348902": [
        {
            "ioc_value": "216.118.101.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-29 13:56:30",
            "last_seen_utc": "2026-10-11 09:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1348295": [
        {
            "ioc_value": "47.90.142.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:54",
            "last_seen_utc": "2026-10-11 09:42:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348026": [
        {
            "ioc_value": "8.137.114.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:07",
            "last_seen_utc": "2026-10-11 09:42:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1346058": [
        {
            "ioc_value": "servicioremotoempresas.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-19 18:00:05",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1344482": [
        {
            "ioc_value": "https://porelinofigoventa.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-11-12 15:05:48",
            "last_seen_utc": "2026-10-11 09:36:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ce9a17687a6aa71b1f382c292a085bd31eb4c15a851cc11e49b1302bd3d1602b/",
            "tags": "Latrodectus",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1340788": [
        {
            "ioc_value": "8.138.155.217:18888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-04 00:01:21",
            "last_seen_utc": "2026-10-10 07:54:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.155.217",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,Supershell",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1340201": [
        {
            "ioc_value": "146.70.158.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-10-30 17:53:55",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Sliver%20C2",
            "tags": "c2,sliver,sliverc2",
            "anonymous": 0,
            "reporter": "TheRavenFile"
        }
    ],
    "1338677": [
        {
            "ioc_value": "https://winarkamaps.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:44",
            "last_seen_utc": "2026-10-11 09:49:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338675": [
        {
            "ioc_value": "https://stripplasst.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:41",
            "last_seen_utc": "2026-10-11 09:43:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338674": [
        {
            "ioc_value": "https://stratimasesstr.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:40",
            "last_seen_utc": "2026-10-11 09:41:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338670": [
        {
            "ioc_value": "https://coolarition.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:34",
            "last_seen_utc": "2026-10-11 08:58:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1332624": [
        {
            "ioc_value": "154.221.17.44:2888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-10-02 06:31:45",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1332328": [
        {
            "ioc_value": "195.100.198.220:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-10-01 16:02:09",
            "last_seen_utc": "2026-10-11 09:44:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.100.198.220",
            "tags": "AS5400,BT,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1330880": [
        {
            "ioc_value": "45.74.34.32:1995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2024-09-27 16:02:26",
            "last_seen_utc": "2026-10-11 09:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.74.34.32",
            "tags": "AS9009,C2,censys,DcRAT,M247,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1329042": [
        {
            "ioc_value": "118.25.148.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-25 08:00:47",
            "last_seen_utc": "2026-10-11 09:42:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.148.25",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1319266": [
        {
            "ioc_value": "154.221.17.44:2666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-01 12:00:42",
            "last_seen_utc": "2026-10-11 09:46:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.221.17.44",
            "tags": "AS142403,C2,censys,CobaltStrike,cs-watermark-666666666,YISUCLOUDLTD-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1317376": [
        {
            "ioc_value": "https://pikchestop.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-10-11 09:37:36",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317377": [
        {
            "ioc_value": "https://indepahote.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-10-11 09:47:38",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1314694": [
        {
            "ioc_value": "83.229.120.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-08-22 10:04:33",
            "last_seen_utc": "2026-10-11 09:45:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.120.73",
            "tags": "AS139659,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313796": [
        {
            "ioc_value": "49.7.54.77:50051",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-20 14:04:24",
            "last_seen_utc": "2026-10-10 07:55:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/49.7.54.77",
            "tags": "AS23724,C2,censys,CHINANET-IDC-BJ-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1309755": [
        {
            "ioc_value": "146.70.158.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-11 21:50:57",
            "last_seen_utc": "2026-10-11 09:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.158.198",
            "tags": "AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1296480": [
        {
            "ioc_value": "43.138.0.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-09 19:05:36",
            "last_seen_utc": "2026-10-11 09:42:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1292905": [
        {
            "ioc_value": "qianxinnbplus.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-03 10:21:02",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291411": [
        {
            "ioc_value": "61.96.204.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:19",
            "last_seen_utc": "2026-10-11 09:45:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.96.204.117",
            "tags": "DREAMX-AS DREAMLINE CO.,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291297": [
        {
            "ioc_value": "londopas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:04",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291296": [
        {
            "ioc_value": "berjimek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:03",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1287670": [
        {
            "ioc_value": "91.199.154.103:34211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-06-22 06:45:48",
            "last_seen_utc": "2026-10-11 09:46:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1285430": [
        {
            "ioc_value": "ieee-ecce.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285431": [
        {
            "ioc_value": "kauzalvip.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285432": [
        {
            "ioc_value": "nakit-yok.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285433": [
        {
            "ioc_value": "nathanhr.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1283657": [
        {
            "ioc_value": "support.whatsappsignup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-10 09:26:05",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,PEG TECH INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1278385": [
        {
            "ioc_value": "static.nvidiadrives.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 19:42:15",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1278172": [
        {
            "ioc_value": "119.91.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 08:38:33",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277937": [
        {
            "ioc_value": "47.109.69.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-01 13:08:25",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277588": [
        {
            "ioc_value": "101.43.32.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-31 12:57:33",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276810": [
        {
            "ioc_value": "asterchildrenshoes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:53:46",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BL Networks,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276802": [
        {
            "ioc_value": "124.223.41.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:52:55",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276786": [
        {
            "ioc_value": "8.210.9.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 10:17:04",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1275630": [
        {
            "ioc_value": "pt-security.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-25 22:18:29",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MTW-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1274726": [
        {
            "ioc_value": "47.92.127.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-24 13:15:35",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1274576": [
        {
            "ioc_value": "38.242.151.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-05-23 18:47:48",
            "last_seen_utc": "2026-10-11 09:45:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.242.151.91",
            "tags": "CONTABO,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273973": [
        {
            "ioc_value": "119.28.83.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-22 11:06:58",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273882": [
        {
            "ioc_value": "51.15.16.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2024-05-21 18:51:48",
            "last_seen_utc": "2026-10-11 09:45:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.16.116",
            "tags": "Online SAS,SocGholish",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273456": [
        {
            "ioc_value": "139.159.203.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-21 12:53:29",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1272788": [
        {
            "ioc_value": "123.58.198.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-19 07:56:13",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271699": [
        {
            "ioc_value": "vip8806.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-16 07:53:43",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS LLC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271605": [
        {
            "ioc_value": "blmdiscount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-10-11 09:42:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271606": [
        {
            "ioc_value": "91.238.181.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271347": [
        {
            "ioc_value": "118.25.85.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 15:33:07",
            "last_seen_utc": "2026-10-11 09:42:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.85.198",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-305419896,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1270684": [
        {
            "ioc_value": "64.7.198.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-14 10:14:21",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BLNWX,CobaltStrike,cs-watermark-426352781",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269727": [
        {
            "ioc_value": "113.31.105.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:31",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "China Telecom (Group),CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269724": [
        {
            "ioc_value": "185.196.8.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:10",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269723": [
        {
            "ioc_value": "action-winds.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:09",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269721": [
        {
            "ioc_value": "microstar.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:08",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267565": [
        {
            "ioc_value": "113.31.106.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 10:14:57",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHINANET-SHANGHAI-MAN China Telecom Group,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267486": [
        {
            "ioc_value": "111.230.12.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 07:48:08",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.230.12.238",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1266959": [
        {
            "ioc_value": "134.122.130.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-06 12:49:25",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263972": [
        {
            "ioc_value": "134.122.130.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-29 12:51:26",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263319": [
        {
            "ioc_value": "124.71.106.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-28 17:59:06",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262666": [
        {
            "ioc_value": "118.31.116.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-26 12:59:31",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262568": [
        {
            "ioc_value": "8.134.11.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-25 22:12:56",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1261845": [
        {
            "ioc_value": "165.227.108.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-24 13:08:20",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-970865301,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260893": [
        {
            "ioc_value": "80.66.75.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:49",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GRIZ-INET-SERVICE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260890": [
        {
            "ioc_value": "101.201.54.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:43",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1259796": [
        {
            "ioc_value": "62.204.41.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-21 15:09:17",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.204.41.11",
            "tags": "AS59425,c2,censys,CobaltStrike,cs-watermark-1580103824,HORIZONMSK-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1252542": [
        {
            "ioc_value": "185.196.10.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-02 10:17:26",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,SIMPLECARRIER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1251779": [
        {
            "ioc_value": "116.62.34.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-30 07:11:21",
            "last_seen_utc": "2026-10-11 09:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60ALIBABA-CN-NET+Hangzhou+Alibaba+Advertising+Co.%2CLtd.%60",
            "tags": "ALIBABA-CN-NET,AS37963,c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1250157": [
        {
            "ioc_value": "soneypaly.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 14:42:02",
            "last_seen_utc": "2026-10-11 09:42:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1249815": [
        {
            "ioc_value": "47.105.69.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 07:57:29",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1245476": [
        {
            "ioc_value": "47.100.87.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-09 20:54:40",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244781": [
        {
            "ioc_value": "194.165.16.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 20:55:37",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244726": [
        {
            "ioc_value": "googlesupportacc.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 10:12:56",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASSEFLOW,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1241656": [
        {
            "ioc_value": "121.43.55.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-21 22:13:19",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1240775": [
        {
            "ioc_value": "https://antyparkov.site/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-02-18 08:49:17",
            "last_seen_utc": "2026-10-11 09:34:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0d185ea3b0a49c2fa65bfd2757c9d0705657f0639fd36f196ac394fcd38c361d/",
            "tags": "Latrodectus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1240774": [
        {
            "ioc_value": "https://saicetyapy.space/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-02-18 08:49:16",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0d185ea3b0a49c2fa65bfd2757c9d0705657f0639fd36f196ac394fcd38c361d/",
            "tags": "Latrodectus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1237623": [
        {
            "ioc_value": "as.regcssv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-07 10:12:22",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,FLYSERVERS-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1237292": [
        {
            "ioc_value": "www.164-90-169-184.cprapid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-06 14:44:02",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.169.184+www.164-90-169-184.cprapid.com",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1236577": [
        {
            "ioc_value": "ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-03 19:38:15",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.22.66.152+ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "tags": "AMAZON-02,AS16509,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1236276": [
        {
            "ioc_value": "20.56.70.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-02 06:00:13",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1235330": [
        {
            "ioc_value": "www.classicstandupcomedy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:36",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1235331": [
        {
            "ioc_value": "whyzup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:35",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1235332": [
        {
            "ioc_value": "www.louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:34",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1235333": [
        {
            "ioc_value": "louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:33",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234854": [
        {
            "ioc_value": "kkudndkwatnfevcaqeefytqnh.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:18",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234859": [
        {
            "ioc_value": "whxzqkbbtzvdyxdeseoiyujzs.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234860": [
        {
            "ioc_value": "uohhunkmnfhbimtagizqgwpmv.to",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234928": [
        {
            "ioc_value": "114.55.133.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:40",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/114.55.133.151",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234304": [
        {
            "ioc_value": "38.147.189.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-24 18:49:24",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.189.199",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1233919": [
        {
            "ioc_value": "www.idn15r69vh3fwhzclfoeuaoy.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-23 13:53:21",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.219.229.99+www.idn15r69vh3fwhzclfoeuaoy.today",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1230909": [
        {
            "ioc_value": "lz4.tiktok123.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-15 16:27:00",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230478": [
        {
            "ioc_value": "164.92.79.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-13 06:47:25",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.79.49",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1230429": [
        {
            "ioc_value": "site.dev.hutechweb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-12 18:36:24",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230076": [
        {
            "ioc_value": "ns1.fiducaire.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230077": [
        {
            "ioc_value": "ns1.asurances.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230078": [
        {
            "ioc_value": "sagsblog.telinduslab.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230079": [
        {
            "ioc_value": "ns1.jocelynhealth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1590258876",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229840": [
        {
            "ioc_value": "ns.emaratalyoum.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-10 10:50:13",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1727139162",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229818": [
        {
            "ioc_value": "130.51.20.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-10 06:48:44",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/130.51.20.64",
            "tags": "Pupy RAT,TZULO",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229817": [
        {
            "ioc_value": "161.35.239.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-10 06:48:20",
            "last_seen_utc": "2026-10-11 09:43:53",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.239.147",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229694": [
        {
            "ioc_value": "emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:19",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229695": [
        {
            "ioc_value": "ns1.emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:17",
            "last_seen_utc": "2026-10-11 09:42:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229661": [
        {
            "ioc_value": "111.92.243.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 08:45:29",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HFTCL-AS-AP High Family Technology Co. Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229599": [
        {
            "ioc_value": "82.65.19.134:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2024-01-09 05:30:32",
            "last_seen_utc": "2026-10-11 09:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.65.19.134",
            "tags": "C2,censys,PROXAD,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228458": [
        {
            "ioc_value": "139.9.62.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 21:31:13",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.9.62.19",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228181": [
        {
            "ioc_value": "101.133.225.51:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 14:48:41",
            "last_seen_utc": "2026-10-11 09:46:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.133.225.51",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1227297": [
        {
            "ioc_value": "106.54.209.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-02 14:31:12",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.54.209.36",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1226488": [
        {
            "ioc_value": "astra4512.startdedicated.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-30 11:33:25",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GD-EMEA-DC-SXB1",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1226314": [
        {
            "ioc_value": "38.147.188.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-12-29 18:48:19",
            "last_seen_utc": "2026-10-11 09:45:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.188.28",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1224105": [
        {
            "ioc_value": "cs.xcb.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-27 22:15:29",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1223678": [
        {
            "ioc_value": "8.140.203.92:7817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-12-26 06:46:27",
            "last_seen_utc": "2026-10-11 09:45:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.203.92",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1223139": [
        {
            "ioc_value": "www.eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-24 02:59:49",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.66.49.194+www.eyefinancemonitor.com",
            "tags": "AMAZON-02,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1221451": [
        {
            "ioc_value": "62.234.27.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-18 05:00:11",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1213636": [
        {
            "ioc_value": "MicrosoftSyst3m.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-16 22:12:14",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1209246": [
        {
            "ioc_value": "unzip2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-04 08:45:50",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1205166": [
        {
            "ioc_value": "techsyscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205167": [
        {
            "ioc_value": "yify88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205165": [
        {
            "ioc_value": "sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:03",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205164": [
        {
            "ioc_value": "americcorp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:02",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1204685": [
        {
            "ioc_value": "tech-guard.vguard.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:09",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/44.204.120.159+tech-guard.vguard.tech",
            "tags": "AMAZON-AES,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1204684": [
        {
            "ioc_value": "manager.moonlighter.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:08",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.190.145.40+manager.moonlighter.space",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1202346": [
        {
            "ioc_value": "www.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-15 09:53:18",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-396590767,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1201432": [
        {
            "ioc_value": "goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-10 15:54:20",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.83.17.116+goocoinorg.com",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1201144": [
        {
            "ioc_value": "101.34.222.38:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-09 17:50:07",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.34.222.38",
            "tags": "C2,censys,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1200343": [
        {
            "ioc_value": "dev.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-09 04:06:44",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/134.209.164.110+dev.theokanegroup.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199506": [
        {
            "ioc_value": "bwyb.love",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 18:07:30",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.242.158.114+bwyb.love",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199160": [
        {
            "ioc_value": "www.sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-05 15:00:42",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.157.149.194+www.sunwu.world",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1192255": [
        {
            "ioc_value": "139.155.148.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-24 10:39:59",
            "last_seen_utc": "2026-10-11 09:42:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.155.148.131",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1191379": [
        {
            "ioc_value": "www.goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-20 21:57:56",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+www.goocoinorg.com&ref=threatfox",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1189545": [
        {
            "ioc_value": "airlinesapp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-16 08:49:32",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1188605": [
        {
            "ioc_value": "lectricelfuel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-13 19:49:34",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+lectricelfuel.com&ref=threatfox",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1187462": [
        {
            "ioc_value": "117.72.8.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-11 12:59:56",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.8.192",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1180378": [
        {
            "ioc_value": "111.229.187.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-30 16:12:13",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1165497": [
        {
            "ioc_value": "igo0gle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-21 09:29:08",
            "last_seen_utc": "2026-10-11 09:42:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-ALVIVA,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1165172": [
        {
            "ioc_value": "8.217.217.243:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-09-20 18:47:20",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.217.217.243",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155921": [
        {
            "ioc_value": "csxv.sec.cm",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-09 20:06:55",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHANGWAY-AS,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155319": [
        {
            "ioc_value": "43.136.38.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-05 21:52:59",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1152278": [
        {
            "ioc_value": "withoutedge.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:05",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152277": [
        {
            "ioc_value": "thconnewfoot.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:04",
            "last_seen_utc": "2026-10-11 09:42:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152274": [
        {
            "ioc_value": "caixas.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-10-11 09:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152275": [
        {
            "ioc_value": "ddllsearch.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-10-11 09:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152276": [
        {
            "ioc_value": "gepcash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-10-11 09:42:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152272": [
        {
            "ioc_value": "amazonclouds.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152273": [
        {
            "ioc_value": "amur-city.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1151932": [
        {
            "ioc_value": "77.74.208.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2023-08-25 06:48:54",
            "last_seen_utc": "2026-10-11 09:45:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.74.208.123",
            "tags": "BRETAGNETELECOM,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1151693": [
        {
            "ioc_value": "43.153.222.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-23 11:56:21",
            "last_seen_utc": "2026-10-11 09:42:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149946": [
        {
            "ioc_value": "pctor.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:05",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149945": [
        {
            "ioc_value": "tehomics.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:04",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149944": [
        {
            "ioc_value": "instant-healthonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:03",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1148731": [
        {
            "ioc_value": "stratpringl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-05 14:38:23",
            "last_seen_utc": "2026-10-11 09:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,PINDC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1148487": [
        {
            "ioc_value": "onlinetechdesk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-04 11:01:52",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146843": [
        {
            "ioc_value": "harmonyshoused.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:25:44",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146834": [
        {
            "ioc_value": "api.office-updates.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:24:41",
            "last_seen_utc": "2026-10-11 09:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-494165167,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146619": [
        {
            "ioc_value": "mkbkygbgwcdc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-02 10:24:58",
            "last_seen_utc": "2026-10-11 09:42:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,KAOPU-HK Kaopu Cloud HK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1140114": [
        {
            "ioc_value": "tcessolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-25 10:17:22",
            "last_seen_utc": "2026-10-11 09:42:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS202973,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1138196": [
        {
            "ioc_value": "rw1.sentrysource.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-15 12:48:31",
            "last_seen_utc": "2026-10-11 09:42:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-93937751,ROGERS-COMMUNICATIONS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1135804": [
        {
            "ioc_value": "pedagogists.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:02",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1135803": [
        {
            "ioc_value": "cdnsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:01",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1134787": [
        {
            "ioc_value": "1.15.248.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-28 22:51:22",
            "last_seen_utc": "2026-10-11 09:42:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134128": [
        {
            "ioc_value": "check1.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:12:17",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134127": [
        {
            "ioc_value": "check.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:11:33",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1133505": [
        {
            "ioc_value": "usadevgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-22 17:12:29",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,WAICORE-TRANSIT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1128165": [
        {
            "ioc_value": "heastings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 22:26:06",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1127715": [
        {
            "ioc_value": "unitechdb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:05",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127713": [
        {
            "ioc_value": "cornptia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127714": [
        {
            "ioc_value": "eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127447": [
        {
            "ioc_value": "surplusofer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-08 16:27:41",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122048": [
        {
            "ioc_value": "dianqi2.dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:42:02",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122047": [
        {
            "ioc_value": "dianqi1.dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:46",
            "last_seen_utc": "2026-10-11 09:46:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122046": [
        {
            "ioc_value": "dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:31",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122045": [
        {
            "ioc_value": "dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:10",
            "last_seen_utc": "2026-10-11 09:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121513": [
        {
            "ioc_value": "update.microsoftkernel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:50:10",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121512": [
        {
            "ioc_value": "update.microsofthk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:49:56",
            "last_seen_utc": "2026-10-11 09:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121462": [
        {
            "ioc_value": "skynet-i.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:36:26",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,STC-AS PJSC Rostelecom Krasnodar",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121460": [
        {
            "ioc_value": "update.microsoftapply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:35:48",
            "last_seen_utc": "2026-10-11 09:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1120772": [
        {
            "ioc_value": "australiansuper.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-23 12:37:36",
            "last_seen_utc": "2026-10-11 09:42:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike,cs-watermark-348901740",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1116637": [
        {
            "ioc_value": "sheersdesigns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:03",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1116636": [
        {
            "ioc_value": "artmicrodesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:02",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1112839": [
        {
            "ioc_value": "situotech.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-06 16:13:31",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,HARMONYHOSTING-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1111492": [
        {
            "ioc_value": "157.245.155.179:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-05 12:42:12",
            "last_seen_utc": "2026-10-11 09:43:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.245.155.179",
            "tags": "DIGITALOCEAN-ASN,Pupy RAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110863": [
        {
            "ioc_value": "39.106.36.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:43",
            "last_seen_utc": "2026-10-11 09:45:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.106.36.96",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110862": [
        {
            "ioc_value": "36.95.131.171:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:41",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.95.131.171",
            "tags": "Deimos,TELKOMNET-AS-AP PT Telekomunikasi Indonesia",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110860": [
        {
            "ioc_value": "18.162.155.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:35",
            "last_seen_utc": "2026-10-11 09:44:05",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.162.155.202",
            "tags": "AMAZON-02,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110859": [
        {
            "ioc_value": "8.218.26.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:33",
            "last_seen_utc": "2026-10-11 09:45:53",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.218.26.114",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110858": [
        {
            "ioc_value": "3.209.12.178:3060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:30",
            "last_seen_utc": "2026-10-11 09:45:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.209.12.178",
            "tags": "AMAZON-AES,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1106335": [
        {
            "ioc_value": "maboloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1106336": [
        {
            "ioc_value": "matong.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1106337": [
        {
            "ioc_value": "sveexec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1103771": [
        {
            "ioc_value": "77.242.250.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-15 12:28:52",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1416875320",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1102558": [
        {
            "ioc_value": "lls-rs.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-12 09:02:56",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1096685": [
        {
            "ioc_value": "iony.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096686": [
        {
            "ioc_value": "office36o.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096683": [
        {
            "ioc_value": "feyrijavac.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096684": [
        {
            "ioc_value": "fidelyus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1095276": [
        {
            "ioc_value": "jacketsupport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 22:27:30",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1095042": [
        {
            "ioc_value": "duckducklive.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 04:51:21",
            "last_seen_utc": "2026-10-11 09:42:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b5da1db6d69f2f872e603beb0f121c68f3320ed33a0c9835bfc1a931d177c947",
            "tags": "391144938,Beacon,Cobalt Strike,CobaltStrike",
            "anonymous": 0,
            "reporter": "AndreGironda"
        }
    ],
    "1094484": [
        {
            "ioc_value": "louvree.abudhabe.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-28 15:52:23",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1826426664,EMIRATES-INTERNET Emirates Internet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1092077": [
        {
            "ioc_value": "jquerymaingame.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092078": [
        {
            "ioc_value": "mail-my-account.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092079": [
        {
            "ioc_value": "my-accounts-gooogle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092080": [
        {
            "ioc_value": "pegistrationads.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092075": [
        {
            "ioc_value": "eaglehardwares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092076": [
        {
            "ioc_value": "information.baby",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092009": [
        {
            "ioc_value": "moviegallerys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 13:36:29",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091575": [
        {
            "ioc_value": "acroserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 22:40:17",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091535": [
        {
            "ioc_value": "atechniques.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 19:45:49",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091454": [
        {
            "ioc_value": "winsatoom.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 13:33:15",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-668694132",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1087542": [
        {
            "ioc_value": "devoinnanote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-13 04:47:12",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-2130772225,SHARKTECH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082976": [
        {
            "ioc_value": "ponzinivek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082977": [
        {
            "ioc_value": "ruplearben.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082978": [
        {
            "ioc_value": "talonbilling.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082979": [
        {
            "ioc_value": "gorillagaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082980": [
        {
            "ioc_value": "chanimoblie.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082975": [
        {
            "ioc_value": "svcshosvt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:08",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082871": [
        {
            "ioc_value": "kbnexc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:02",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082870": [
        {
            "ioc_value": "jquerysslx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:01",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082838": [
        {
            "ioc_value": "e-servicesolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 13:15:07",
            "last_seen_utc": "2026-10-11 09:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA GROUP Ltd,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082591": [
        {
            "ioc_value": "devsecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-24 02:30:56",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082419": [
        {
            "ioc_value": "vmware.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-23 13:06:09",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1081264": [
        {
            "ioc_value": "85.175.101.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-19 23:10:55",
            "last_seen_utc": "2026-10-11 09:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,STC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1081018": [
        {
            "ioc_value": "galspost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-17 18:25:01",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1101991775,Microsoft Corporation",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1080735": [
        {
            "ioc_value": "imvcatool.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-16 14:54:22",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1080316": [
        {
            "ioc_value": "37.119.57.195:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2023-02-14 18:50:35",
            "last_seen_utc": "2026-10-11 09:45:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.119.57.195",
            "tags": "Brute Ratel C4,VODAFONE-IT-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078198": [
        {
            "ioc_value": "aspnetcenter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 19:39:46",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Web Gostaran Bandar Company PJS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078172": [
        {
            "ioc_value": "audelr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078173": [
        {
            "ioc_value": "csou.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078174": [
        {
            "ioc_value": "integrated-security.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078175": [
        {
            "ioc_value": "uranustechsolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078062": [
        {
            "ioc_value": "getsafeblog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 17:24:39",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1076896": [
        {
            "ioc_value": "nxsimdevelop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:39:18",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075651": [
        {
            "ioc_value": "appdevtechnology.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-01 02:21:19",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075540": [
        {
            "ioc_value": "dbx.formsift.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-31 15:09:13",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075020": [
        {
            "ioc_value": "devcloudpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-29 11:29:55",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074894": [
        {
            "ioc_value": "164.90.158.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:24",
            "last_seen_utc": "2026-10-11 09:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.158.199",
            "tags": "DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074144": [
        {
            "ioc_value": "support-wellsfargovis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:03",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074140": [
        {
            "ioc_value": "execsvct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074141": [
        {
            "ioc_value": "recoverporta1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074142": [
        {
            "ioc_value": "recoverportal2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074143": [
        {
            "ioc_value": "recoveryweb2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1073670": [
        {
            "ioc_value": "vd-ntds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-23 20:33:42",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1070164": [
        {
            "ioc_value": "hnsxpharm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070165": [
        {
            "ioc_value": "myjqueryss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070166": [
        {
            "ioc_value": "svcrencst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070167": [
        {
            "ioc_value": "telusmobility-billed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070168": [
        {
            "ioc_value": "thenbkgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070137": [
        {
            "ioc_value": "avdev.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 11:23:14",
            "last_seen_utc": "2026-10-11 09:42:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069895": [
        {
            "ioc_value": "azurecloudfire.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 14:15:53",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ITRESHENIYA-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069868": [
        {
            "ioc_value": "goupdatemic.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 11:23:42",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GOOGLE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069579": [
        {
            "ioc_value": "mwg-update.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-18 02:29:29",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068206": [
        {
            "ioc_value": "goodsport2023.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-13 17:37:32",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,VOM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068079": [
        {
            "ioc_value": "blackandwhiteshoose.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 21:56:23",
            "last_seen_utc": "2026-10-11 09:42:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067954": [
        {
            "ioc_value": "realsecuritystore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 14:45:18",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067924": [
        {
            "ioc_value": "fixx.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 13:04:56",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SNEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067646": [
        {
            "ioc_value": "allowedcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-11 10:59:45",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HIVELOCITY Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064361": [
        {
            "ioc_value": "www.linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-02 10:24:29",
            "last_seen_utc": "2026-10-11 09:42:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Anchnet Asia Limited,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064196": [
        {
            "ioc_value": "freegaysnews.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 19:48:39",
            "last_seen_utc": "2026-10-11 09:42:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064176": [
        {
            "ioc_value": "topgamenetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 18:58:09",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064172": [
        {
            "ioc_value": "wv2022.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064173": [
        {
            "ioc_value": "zfuxwvouqvnttpsrxe.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064075": [
        {
            "ioc_value": "cloudyspaces.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064076": [
        {
            "ioc_value": "666621.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064069": [
        {
            "ioc_value": "144.217.207.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064070": [
        {
            "ioc_value": "allsdone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064071": [
        {
            "ioc_value": "ipsandwich.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064072": [
        {
            "ioc_value": "cookieholder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064073": [
        {
            "ioc_value": "pingcheker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064074": [
        {
            "ioc_value": "wagonovk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064062": [
        {
            "ioc_value": "microsoftupdateassist.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064063": [
        {
            "ioc_value": "qvibova.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064064": [
        {
            "ioc_value": "cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064065": [
        {
            "ioc_value": "metalkost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064066": [
        {
            "ioc_value": "m7r4r2i2.stackpathcdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064067": [
        {
            "ioc_value": "online.cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064057": [
        {
            "ioc_value": "bartiba.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064058": [
        {
            "ioc_value": "varnart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064059": [
        {
            "ioc_value": "nsfdfdfdf.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064060": [
        {
            "ioc_value": "micorsoft.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064061": [
        {
            "ioc_value": "aigouing.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064046": [
        {
            "ioc_value": "ksplsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064047": [
        {
            "ioc_value": "lastinsuranceteam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064048": [
        {
            "ioc_value": "msdnsservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064049": [
        {
            "ioc_value": "securequoteme.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064050": [
        {
            "ioc_value": "techdevcorp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064051": [
        {
            "ioc_value": "syncorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064052": [
        {
            "ioc_value": "visualstudioapp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064053": [
        {
            "ioc_value": "altreeservicellc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064054": [
        {
            "ioc_value": "discountshadesdirect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064055": [
        {
            "ioc_value": "setechnowork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064056": [
        {
            "ioc_value": "technicollit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064038": [
        {
            "ioc_value": "shiyicaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064039": [
        {
            "ioc_value": "cdn-top.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064040": [
        {
            "ioc_value": "onesecondservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064041": [
        {
            "ioc_value": "vpnupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064042": [
        {
            "ioc_value": "rodinscoldly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064043": [
        {
            "ioc_value": "antariscapital.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064044": [
        {
            "ioc_value": "ftwealthmgt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064045": [
        {
            "ioc_value": "iconiq-capitel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064031": [
        {
            "ioc_value": "asset-trades.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064032": [
        {
            "ioc_value": "telemetrin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064033": [
        {
            "ioc_value": "secupdate4win.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064034": [
        {
            "ioc_value": "cdn-start.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064035": [
        {
            "ioc_value": "capitalmanagementdata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064036": [
        {
            "ioc_value": "lawsolutions.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064024": [
        {
            "ioc_value": "diegomaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064025": [
        {
            "ioc_value": "dp-test1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064026": [
        {
            "ioc_value": "cloudkey.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064027": [
        {
            "ioc_value": "updatevpncitrix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064028": [
        {
            "ioc_value": "classgum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064029": [
        {
            "ioc_value": "edgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064030": [
        {
            "ioc_value": "gfcbm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064016": [
        {
            "ioc_value": "barmnava.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064017": [
        {
            "ioc_value": "firewallwithadvancedserurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064018": [
        {
            "ioc_value": "lgbtqplusfriendlydomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064019": [
        {
            "ioc_value": "market-stats.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064020": [
        {
            "ioc_value": "apabfs.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064021": [
        {
            "ioc_value": "fziomerof.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064022": [
        {
            "ioc_value": "fserd.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064023": [
        {
            "ioc_value": "verofes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064015": [
        {
            "ioc_value": "postofficeltdc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:43",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064006": [
        {
            "ioc_value": "jarvcza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064007": [
        {
            "ioc_value": "teystyjeem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064008": [
        {
            "ioc_value": "faceupfinder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064009": [
        {
            "ioc_value": "costacancordia.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064010": [
        {
            "ioc_value": "lapsusareskids.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064011": [
        {
            "ioc_value": "msupdater.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064012": [
        {
            "ioc_value": "dwordname.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064013": [
        {
            "ioc_value": "trademot.finance",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064014": [
        {
            "ioc_value": "agreminj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063998": [
        {
            "ioc_value": "exchangeallltd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063999": [
        {
            "ioc_value": "guggenheimpartners-survey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064000": [
        {
            "ioc_value": "caresalonservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064001": [
        {
            "ioc_value": "just-findncall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064002": [
        {
            "ioc_value": "fluoxi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064003": [
        {
            "ioc_value": "buynet.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064004": [
        {
            "ioc_value": "everythingchecker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064005": [
        {
            "ioc_value": "dezword.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063995": [
        {
            "ioc_value": "goksearch.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063996": [
        {
            "ioc_value": "polyhaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063997": [
        {
            "ioc_value": "data-protection-test.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063992": [
        {
            "ioc_value": "update04.microsoft-essentials.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:39",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063991": [
        {
            "ioc_value": "akaluij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:38",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063989": [
        {
            "ioc_value": "43.129.7.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063990": [
        {
            "ioc_value": "82.156.241.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063985": [
        {
            "ioc_value": "donormix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063986": [
        {
            "ioc_value": "hardicki.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063987": [
        {
            "ioc_value": "stfconnect.onthewifi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063988": [
        {
            "ioc_value": "agsdef.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063978": [
        {
            "ioc_value": "observerinfo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063979": [
        {
            "ioc_value": "dehikz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063980": [
        {
            "ioc_value": "cocanewline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063981": [
        {
            "ioc_value": "rainqor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063982": [
        {
            "ioc_value": "axelkim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063983": [
        {
            "ioc_value": "azimurs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063984": [
        {
            "ioc_value": "innovativesitecreations.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063972": [
        {
            "ioc_value": "creditscore.usbankcreditcards.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063975": [
        {
            "ioc_value": "megumin.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063976": [
        {
            "ioc_value": "loanhelp.support",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063977": [
        {
            "ioc_value": "volsecure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063966": [
        {
            "ioc_value": "domtern.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063967": [
        {
            "ioc_value": "topsmartservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063968": [
        {
            "ioc_value": "drakr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063969": [
        {
            "ioc_value": "devcisco.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063970": [
        {
            "ioc_value": "top-business-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063971": [
        {
            "ioc_value": "web-news-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063963": [
        {
            "ioc_value": "bankafrika.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063964": [
        {
            "ioc_value": "mssfr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063965": [
        {
            "ioc_value": "edgekey.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063955": [
        {
            "ioc_value": "webyoutubeshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063956": [
        {
            "ioc_value": "extic.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063957": [
        {
            "ioc_value": "reykh.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063958": [
        {
            "ioc_value": "onemusic24.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063959": [
        {
            "ioc_value": "propertynewsclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063960": [
        {
            "ioc_value": "afindisc.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063961": [
        {
            "ioc_value": "propertyinfogroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063962": [
        {
            "ioc_value": "topnewscompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063950": [
        {
            "ioc_value": "baidenfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063951": [
        {
            "ioc_value": "directoryupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063952": [
        {
            "ioc_value": "azmnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063953": [
        {
            "ioc_value": "onevisioncommunications.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063954": [
        {
            "ioc_value": "campioni-imam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063943": [
        {
            "ioc_value": "serviceapp1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063944": [
        {
            "ioc_value": "softcloud.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063945": [
        {
            "ioc_value": "appmind.center",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063946": [
        {
            "ioc_value": "ms-data.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063947": [
        {
            "ioc_value": "oracleup.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063948": [
        {
            "ioc_value": "topinfocompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063949": [
        {
            "ioc_value": "blockchainstartups-crypto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063934": [
        {
            "ioc_value": "expresssmash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063935": [
        {
            "ioc_value": "vgroz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063936": [
        {
            "ioc_value": "baidengop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063937": [
        {
            "ioc_value": "ofilopex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063938": [
        {
            "ioc_value": "aabancaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063939": [
        {
            "ioc_value": "shermango.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063940": [
        {
            "ioc_value": "nongxinyin.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063941": [
        {
            "ioc_value": "a6m1n.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063942": [
        {
            "ioc_value": "emailbox.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063926": [
        {
            "ioc_value": "wxtencent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063927": [
        {
            "ioc_value": "emergeno.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063928": [
        {
            "ioc_value": "browngreeer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063929": [
        {
            "ioc_value": "processdec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063930": [
        {
            "ioc_value": "dropklant.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063931": [
        {
            "ioc_value": "sndm-sndm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063932": [
        {
            "ioc_value": "sinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063933": [
        {
            "ioc_value": "vinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063918": [
        {
            "ioc_value": "westtherr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063919": [
        {
            "ioc_value": "quickaccestwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063920": [
        {
            "ioc_value": "usgrim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063921": [
        {
            "ioc_value": "onelivemusicshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063922": [
        {
            "ioc_value": "zomerax.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063923": [
        {
            "ioc_value": "fsamon.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063924": [
        {
            "ioc_value": "sscimails.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063925": [
        {
            "ioc_value": "agentrecovery.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063909": [
        {
            "ioc_value": "entertainok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063910": [
        {
            "ioc_value": "jatafatuna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063911": [
        {
            "ioc_value": "pluyk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063912": [
        {
            "ioc_value": "affinm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063913": [
        {
            "ioc_value": "gijoxupe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063914": [
        {
            "ioc_value": "vangshares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063915": [
        {
            "ioc_value": "fudupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063916": [
        {
            "ioc_value": "theinfoinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063917": [
        {
            "ioc_value": "contemporaryto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063902": [
        {
            "ioc_value": "ziono.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063903": [
        {
            "ioc_value": "lolutow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063904": [
        {
            "ioc_value": "niht12.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063905": [
        {
            "ioc_value": "slfcorporate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063906": [
        {
            "ioc_value": "baidu-cdn-10.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063907": [
        {
            "ioc_value": "jandoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063908": [
        {
            "ioc_value": "casevor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063897": [
        {
            "ioc_value": "gotroops.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063898": [
        {
            "ioc_value": "wtxservice.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063899": [
        {
            "ioc_value": "xevayuhace.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063900": [
        {
            "ioc_value": "suppcat.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063901": [
        {
            "ioc_value": "softloadup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063889": [
        {
            "ioc_value": "asbetysh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063890": [
        {
            "ioc_value": "ascagliarinish.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063891": [
        {
            "ioc_value": "ascasdsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063892": [
        {
            "ioc_value": "aschamp79sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063893": [
        {
            "ioc_value": "aschnurmansh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063894": [
        {
            "ioc_value": "aseleeeksh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063895": [
        {
            "ioc_value": "asensvsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063880": [
        {
            "ioc_value": "artist2actresssh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063881": [
        {
            "ioc_value": "arturprikhodkosh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063882": [
        {
            "ioc_value": "arvin78sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063883": [
        {
            "ioc_value": "arvind567shahsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063884": [
        {
            "ioc_value": "arvindkkumsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063885": [
        {
            "ioc_value": "arvosash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063886": [
        {
            "ioc_value": "arwalsersh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063887": [
        {
            "ioc_value": "aryaarieash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063888": [
        {
            "ioc_value": "aryalalexsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063870": [
        {
            "ioc_value": "dovaxanil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063871": [
        {
            "ioc_value": "hehegahu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063872": [
        {
            "ioc_value": "agriculturemachineries.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063873": [
        {
            "ioc_value": "arhipenkolenagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063874": [
        {
            "ioc_value": "aritmiagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063875": [
        {
            "ioc_value": "artes911sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063876": [
        {
            "ioc_value": "arthas89sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063877": [
        {
            "ioc_value": "arthurstevens62sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063878": [
        {
            "ioc_value": "arthurtaylor13sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063879": [
        {
            "ioc_value": "artis214sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-10-11 09:42:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063864": [
        {
            "ioc_value": "zipo-cons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063865": [
        {
            "ioc_value": "fazehotafa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063866": [
        {
            "ioc_value": "zendriol.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063867": [
        {
            "ioc_value": "sezezapa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063868": [
        {
            "ioc_value": "sorekipe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063869": [
        {
            "ioc_value": "zezinuwe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063858": [
        {
            "ioc_value": "shrekf.art",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063859": [
        {
            "ioc_value": "amaniza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063860": [
        {
            "ioc_value": "microcloud.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063861": [
        {
            "ioc_value": "anexuss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063862": [
        {
            "ioc_value": "edictsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063863": [
        {
            "ioc_value": "out1etshops.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063851": [
        {
            "ioc_value": "stepnbayac.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063852": [
        {
            "ioc_value": "chickenpoken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063853": [
        {
            "ioc_value": "hockeysmall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063854": [
        {
            "ioc_value": "orthodoxok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063855": [
        {
            "ioc_value": "cocesovo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063856": [
        {
            "ioc_value": "familyinsurancepartner.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063857": [
        {
            "ioc_value": "senebuvuyi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063848": [
        {
            "ioc_value": "fincheck.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063849": [
        {
            "ioc_value": "svchosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063850": [
        {
            "ioc_value": "conhosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063843": [
        {
            "ioc_value": "maximumservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063844": [
        {
            "ioc_value": "conferencedesk.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063845": [
        {
            "ioc_value": "bluetechsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063846": [
        {
            "ioc_value": "allgroupservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063847": [
        {
            "ioc_value": "acitopram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063838": [
        {
            "ioc_value": "businessservicesolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063839": [
        {
            "ioc_value": "gravyblicus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063840": [
        {
            "ioc_value": "firmwarekey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063841": [
        {
            "ioc_value": "updateraccount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063842": [
        {
            "ioc_value": "mvnetworking.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063832": [
        {
            "ioc_value": "avasecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063833": [
        {
            "ioc_value": "extranetserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063834": [
        {
            "ioc_value": "clacem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063835": [
        {
            "ioc_value": "eonline-cdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063836": [
        {
            "ioc_value": "cagohufe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063837": [
        {
            "ioc_value": "vezawahoy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063826": [
        {
            "ioc_value": "tetafup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063827": [
        {
            "ioc_value": "api-trend-micro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063828": [
        {
            "ioc_value": "digital-hardware.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063829": [
        {
            "ioc_value": "aboutdatabasesoftware.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063830": [
        {
            "ioc_value": "high-control.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063831": [
        {
            "ioc_value": "soft-base.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063821": [
        {
            "ioc_value": "iptvr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063822": [
        {
            "ioc_value": "microsofer.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063823": [
        {
            "ioc_value": "mingw.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063824": [
        {
            "ioc_value": "transfercloud.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063825": [
        {
            "ioc_value": "flashcom.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063818": [
        {
            "ioc_value": "sciencelifedata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063819": [
        {
            "ioc_value": "bookingsupport.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063820": [
        {
            "ioc_value": "ateyakima.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063813": [
        {
            "ioc_value": "buy1walmart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063814": [
        {
            "ioc_value": "stakcl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063816": [
        {
            "ioc_value": "drbeat.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063817": [
        {
            "ioc_value": "aialadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063810": [
        {
            "ioc_value": "hhkj222.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063811": [
        {
            "ioc_value": "yw2204.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063812": [
        {
            "ioc_value": "nordicqlobal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063806": [
        {
            "ioc_value": "favls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063807": [
        {
            "ioc_value": "linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063808": [
        {
            "ioc_value": "magellanfit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063809": [
        {
            "ioc_value": "conhoosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063805": [
        {
            "ioc_value": "afspd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:03",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063804": [
        {
            "ioc_value": "164.92.70.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:46:51",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063802": [
        {
            "ioc_value": "abritrum-bridges.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:44:07",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063123": [
        {
            "ioc_value": "apacheorg.wiki",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 02:22:09",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDIE-AS-AP Cloudie Limited,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1062406": [
        {
            "ioc_value": "updatemicrotok.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-24 19:00:50",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SERVERION,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1053949": [
        {
            "ioc_value": "eserverx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 21:43:42",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050306": [
        {
            "ioc_value": "cmdatabase.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 11:41:44",
            "last_seen_utc": "2026-10-11 09:42:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ADM Service Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050198": [
        {
            "ioc_value": "cloudmane.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-17 12:12:59",
            "last_seen_utc": "2026-10-11 09:42:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036758": [
        {
            "ioc_value": "8.212.49.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-13 11:43:38",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Alibaba (US) Technology Co. Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035723": [
        {
            "ioc_value": "expoglobalservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-08 20:45:56",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TIER-NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1031731": [
        {
            "ioc_value": "googlecontentuser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 20:03:53",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/TheDFIRReport/status/1599780643222654976",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1031726": [
        {
            "ioc_value": "test.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 19:27:32",
            "last_seen_utc": "2026-10-11 09:42:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YISUCLOUDLTD-HK YISU CLOUD LTD",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1029025": [
        {
            "ioc_value": "palalto.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 11:42:38",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028963": [
        {
            "ioc_value": "esoftwareupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-04 20:18:27",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASGHOSTNET,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028767": [
        {
            "ioc_value": "globalplayservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 21:28:11",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028737": [
        {
            "ioc_value": "rapidfinact.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:50:52",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028720": [
        {
            "ioc_value": "globalsteamclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:38:18",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028501": [
        {
            "ioc_value": "get-music-online.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-01 20:32:20",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1024554": [
        {
            "ioc_value": "msndla.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-27 16:10:54",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023854": [
        {
            "ioc_value": "childhealthresources.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:54:46",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023821": [
        {
            "ioc_value": "360safeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:50:52",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1021044": [
        {
            "ioc_value": "aksaholdings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-20 10:32:06",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1012628": [
        {
            "ioc_value": "msisfx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-15 06:56:25",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/malware_traffic/status/1592262598195646464",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1009773": [
        {
            "ioc_value": "get-smartbuyer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-12 17:46:46",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "991420": [
        {
            "ioc_value": "sogouupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-08 20:20:30",
            "last_seen_utc": "2026-10-11 09:42:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "985010": [
        {
            "ioc_value": "dnsupdatecheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-07 20:10:29",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "973832": [
        {
            "ioc_value": "ipulsecloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-04 11:23:08",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "964538": [
        {
            "ioc_value": "zadiguser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964540": [
        {
            "ioc_value": "wasazokiwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964541": [
        {
            "ioc_value": "yuwajeni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964542": [
        {
            "ioc_value": "yavahiyil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964543": [
        {
            "ioc_value": "rabihino.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964545": [
        {
            "ioc_value": "nokevohoh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964546": [
        {
            "ioc_value": "rawocav.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964548": [
        {
            "ioc_value": "deyikurihe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "952862": [
        {
            "ioc_value": "freshuper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-30 19:51:44",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,tzulo inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952596": [
        {
            "ioc_value": "reebons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:32:13",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952587": [
        {
            "ioc_value": "gaswert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:23:49",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952582": [
        {
            "ioc_value": "sajij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 11:54:42",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952555": [
        {
            "ioc_value": "asasyz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:14:36",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952552": [
        {
            "ioc_value": "agazud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:12:26",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LLC Baxet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952534": [
        {
            "ioc_value": "tuuik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:57:36",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952528": [
        {
            "ioc_value": "alfuhin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:56:46",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "950974": [
        {
            "ioc_value": "amaladin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-27 23:43:27",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "949937": [
        {
            "ioc_value": "aualadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-26 10:09:11",
            "last_seen_utc": "2026-10-11 09:42:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916136": [
        {
            "ioc_value": "bthserv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:42:10",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Internet Solutions & Innovations LTD.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916115": [
        {
            "ioc_value": "nuesro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:37:35",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916100": [
        {
            "ioc_value": "pasadonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:36:50",
            "last_seen_utc": "2026-10-11 09:42:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915911": [
        {
            "ioc_value": "worldsgates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:40:40",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LUCIDACLOUD LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915908": [
        {
            "ioc_value": "protramal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:39:30",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915846": [
        {
            "ioc_value": "spltst.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 01:11:02",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,combahton GmbH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891477": [
        {
            "ioc_value": "cehocihit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 13:10:54",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891461": [
        {
            "ioc_value": "cloudmicro.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 12:38:04",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "887212": [
        {
            "ioc_value": "keycloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:41:28",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PARTNER-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886703": [
        {
            "ioc_value": "activeservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:13:41",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amati Foundation,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886693": [
        {
            "ioc_value": "newyearbalance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:12:51",
            "last_seen_utc": "2026-10-11 09:42:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886516": [
        {
            "ioc_value": "xamayojir.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:02:36",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886499": [
        {
            "ioc_value": "xicefoga.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 20:58:25",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-WDC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "884091": [
        {
            "ioc_value": "ams-prd-cob.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:51:56",
            "last_seen_utc": "2026-10-11 09:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883488": [
        {
            "ioc_value": "tagujog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:35:22",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883412": [
        {
            "ioc_value": "mysqlserver.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:32:23",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ICME",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883142": [
        {
            "ioc_value": "xuluxetas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:23:44",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-NYC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "880419": [
        {
            "ioc_value": "hadujaza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-12 17:16:11",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871733": [
        {
            "ioc_value": "softsupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871734": [
        {
            "ioc_value": "anushl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858399": [
        {
            "ioc_value": "anbush.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858402": [
        {
            "ioc_value": "get-topservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-10-11 09:42:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858403": [
        {
            "ioc_value": "msoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858404": [
        {
            "ioc_value": "pregabas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-10-11 09:42:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "851096": [
        {
            "ioc_value": "34.92.131.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-22 11:26:18",
            "last_seen_utc": "2026-10-11 09:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Google LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "850706": [
        {
            "ioc_value": "87.246.7.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:58:14",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850701": [
        {
            "ioc_value": "cloudmicro.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850702": [
        {
            "ioc_value": "fregiyu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-10-11 09:42:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850704": [
        {
            "ioc_value": "microcloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-10-11 09:42:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850260": [
        {
            "ioc_value": "154.22.117.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-17 21:24:41",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Cogent Communications",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "849761": [
        {
            "ioc_value": "198.98.53.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-14 22:07:14",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "847988": [
        {
            "ioc_value": "globallookclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:52",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847986": [
        {
            "ioc_value": "realfunsolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:50",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847973": [
        {
            "ioc_value": "service1app.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847975": [
        {
            "ioc_value": "youronlinesports.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847976": [
        {
            "ioc_value": "yourinfosolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847983": [
        {
            "ioc_value": "jacollans.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847941": [
        {
            "ioc_value": "onestepstar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847942": [
        {
            "ioc_value": "satorkar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847957": [
        {
            "ioc_value": "realmacnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847958": [
        {
            "ioc_value": "onemusicllc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847959": [
        {
            "ioc_value": "ateliernow.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847929": [
        {
            "ioc_value": "sprinthunter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847930": [
        {
            "ioc_value": "newstamagavk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847028": [
        {
            "ioc_value": "barabezo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 18:29:19",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0e/",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847018": [
        {
            "ioc_value": "alojun.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847019": [
        {
            "ioc_value": "asdder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-10-11 09:42:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847021": [
        {
            "ioc_value": "zominoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-10-11 09:42:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "846258": [
        {
            "ioc_value": "jevomukif.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-30 06:22:11",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-29-IOCs-for-Monster-Libra-TA551-IcedID-with-Cobalt-Stike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844214": [
        {
            "ioc_value": "msdnupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-10-11 09:43:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844215": [
        {
            "ioc_value": "msdupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-10-11 09:43:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843958": [
        {
            "ioc_value": "caxoxc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-18 12:15:06",
            "last_seen_utc": "2026-10-11 09:43:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843546": [
        {
            "ioc_value": "47.108.180.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-16 11:38:21",
            "last_seen_utc": "2026-10-11 09:42:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "842464": [
        {
            "ioc_value": "jahojahi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-11 06:03:19",
            "last_seen_utc": "2026-10-11 09:42:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-10-IOCs-for-IcedID-and-Cobalt-Strike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "841794": [
        {
            "ioc_value": "http://89.185.85.53/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.recordbreaker",
            "malware_alias": null,
            "malware_printable": "RecordBreaker",
            "first_seen_utc": "2022-08-07 13:15:28",
            "last_seen_utc": "2026-10-10 16:25:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RecordBreaker",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "841613": [
        {
            "ioc_value": "zambeziz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-06 07:00:06",
            "last_seen_utc": "2026-10-11 09:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltSrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "839793": [
        {
            "ioc_value": "zuyonijobo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-27 08:49:04",
            "last_seen_utc": "2026-10-11 09:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://isc.sans.edu/diary/28884",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "802793": [
        {
            "ioc_value": "digerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-06 05:36:04",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "796822": [
        {
            "ioc_value": "chitozx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-05 05:12:06",
            "last_seen_utc": "2026-10-11 09:43:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "750750": [
        {
            "ioc_value": "42.192.21.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-02 13:06:49",
            "last_seen_utc": "2026-10-11 09:42:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "730561": [
        {
            "ioc_value": "18.117.254.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-28 08:57:21",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "729038": [
        {
            "ioc_value": "blinkinuf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:33",
            "last_seen_utc": "2026-10-11 09:43:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "729037": [
        {
            "ioc_value": "malrok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:32",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720823": [
        {
            "ioc_value": "trumpiko.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720824": [
        {
            "ioc_value": "freygor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720826": [
        {
            "ioc_value": "sinjoan.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720827": [
        {
            "ioc_value": "afluix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720273": [
        {
            "ioc_value": "www.edge-chrome.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720276": [
        {
            "ioc_value": "www.hellomrsone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720263": [
        {
            "ioc_value": "wpsserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720248": [
        {
            "ioc_value": "thedaily-news.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:18",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720239": [
        {
            "ioc_value": "sevenhungredbucks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720241": [
        {
            "ioc_value": "snccoupr-int.cf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720247": [
        {
            "ioc_value": "telembank.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720230": [
        {
            "ioc_value": "ppew.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720231": [
        {
            "ioc_value": "pretunz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720237": [
        {
            "ioc_value": "scarfaceserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720226": [
        {
            "ioc_value": "outlet-studio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:15",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720208": [
        {
            "ioc_value": "js.msedgeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:14",
            "last_seen_utc": "2026-10-11 09:42:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720198": [
        {
            "ioc_value": "harborfreight.delivery",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-10-11 09:43:30",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720201": [
        {
            "ioc_value": "hityok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720203": [
        {
            "ioc_value": "jiguz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720204": [
        {
            "ioc_value": "jijuanjo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720206": [
        {
            "ioc_value": "jqueryupdatenow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720207": [
        {
            "ioc_value": "jqueryupneed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720188": [
        {
            "ioc_value": "fifacud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-10-11 09:43:09",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720189": [
        {
            "ioc_value": "filaspo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720193": [
        {
            "ioc_value": "gasienda.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720185": [
        {
            "ioc_value": "dreamkoks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:11",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720176": [
        {
            "ioc_value": "democrazzy.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:10",
            "last_seen_utc": "2026-10-11 09:42:59",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720156": [
        {
            "ioc_value": "cloud.sovarermscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:31",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720136": [
        {
            "ioc_value": "backupcreds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-10-11 09:43:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720140": [
        {
            "ioc_value": "biohazzzard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-10-11 09:43:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720141": [
        {
            "ioc_value": "bksfinance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720143": [
        {
            "ioc_value": "boronab.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-10-11 09:43:10",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720132": [
        {
            "ioc_value": "araizx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-10-11 09:43:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720133": [
        {
            "ioc_value": "arminext.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "719898": [
        {
            "ioc_value": "aginij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-22 18:35:13",
            "last_seen_utc": "2026-10-11 09:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "710534": [
        {
            "ioc_value": "85.175.101.203:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-15 20:53:40",
            "last_seen_utc": "2026-10-11 09:46:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,STC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "606362": [
        {
            "ioc_value": "criobob.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606363": [
        {
            "ioc_value": "prozakx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606364": [
        {
            "ioc_value": "terroklo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606360": [
        {
            "ioc_value": "microdozz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:57",
            "last_seen_utc": "2026-10-11 09:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "549372": [
        {
            "ioc_value": "us189-hpgsgae5dva9fzch.z01.azurefd.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-10 18:53:07",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,threatview.io",
            "anonymous": 0,
            "reporter": "Malwar3Ninja"
        }
    ],
    "548951": [
        {
            "ioc_value": "artidomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-08 16:20:03",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/ian_kenefick/status/1523288477559062529",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "544836": [
        {
            "ioc_value": "116.62.185.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-30 19:45:18",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "540702": [
        {
            "ioc_value": "165.227.180.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-29 19:30:18",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "532916": [
        {
            "ioc_value": "120.26.240.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-25 12:31:07",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "530098": [
        {
            "ioc_value": "193.29.13.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-23 16:42:50",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "***************************************,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "523516": [
        {
            "ioc_value": "45.8.158.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-21 16:54:57",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASBAXETN,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521565": [
        {
            "ioc_value": "115.29.171.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-19 13:44:33",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521083": [
        {
            "ioc_value": "84.32.188.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-18 18:01:52",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "520317": [
        {
            "ioc_value": "137.184.42.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-15 22:57:51",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519914": [
        {
            "ioc_value": "84.32.188.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 16:59:25",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519792": [
        {
            "ioc_value": "furfen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 10:30:57",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BumbleBee,Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "519116": [
        {
            "ioc_value": "175.41.21.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-13 16:57:52",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518853": [
        {
            "ioc_value": "175.41.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-12 16:50:58",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518404": [
        {
            "ioc_value": "138.68.110.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-10 17:05:31",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "516676": [
        {
            "ioc_value": "13.55.118.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-06 22:59:35",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "493695": [
        {
            "ioc_value": "185.186.143.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 22:55:20",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASKONTEL,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "492845": [
        {
            "ioc_value": "194.37.97.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 16:53:16",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247 Ltd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "466600": [
        {
            "ioc_value": "blopik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-30 09:51:36",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "461231": [
        {
            "ioc_value": "borizhog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-29 08:36:59",
            "last_seen_utc": "2026-10-11 09:43:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "448027": [
        {
            "ioc_value": "37.72.172.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 22:55:12",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "446029": [
        {
            "ioc_value": "1.14.76.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 10:56:07",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443786": [
        {
            "ioc_value": "139.60.160.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 20:44:05",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443190": [
        {
            "ioc_value": "apeduze.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 16:44:21",
            "last_seen_utc": "2026-10-11 09:43:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438442": [
        {
            "ioc_value": "drimzis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438443": [
        {
            "ioc_value": "blinkij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "398650": [
        {
            "ioc_value": "152.136.178.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 22:47:07",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "397514": [
        {
            "ioc_value": "150.109.103.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 20:44:20",
            "last_seen_utc": "2026-10-10 09:30:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "396104": [
        {
            "ioc_value": "dunclikf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 12:19:46",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393426": [
        {
            "ioc_value": "sifgu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393427": [
        {
            "ioc_value": "gfsert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393429": [
        {
            "ioc_value": "shizij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393430": [
        {
            "ioc_value": "zxerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393431": [
        {
            "ioc_value": "korunder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393424": [
        {
            "ioc_value": "chesft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393425": [
        {
            "ioc_value": "uktyl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-10-11 09:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393312": [
        {
            "ioc_value": "defenr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393313": [
        {
            "ioc_value": "fedij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393314": [
        {
            "ioc_value": "kejimn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393311": [
        {
            "ioc_value": "brikeb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:34",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393046": [
        {
            "ioc_value": "kapuleti.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-08 17:09:32",
            "last_seen_utc": "2026-10-11 09:43:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "392705": [
        {
            "ioc_value": "45.12.1.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-06 16:43:33",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392630": [
        {
            "ioc_value": "45.12.1.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:45:53",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392595": [
        {
            "ioc_value": "45.12.1.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:43:28",
            "last_seen_utc": "2026-10-11 09:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDNETWORKS-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "391528": [
        {
            "ioc_value": "defegh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391530": [
        {
            "ioc_value": "klycnmik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391531": [
        {
            "ioc_value": "ngrety.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-10-11 09:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391111": [
        {
            "ioc_value": "lifegothistory.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-27 06:03:58",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1497771037718724612",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "390123": [
        {
            "ioc_value": "192.241.133.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:44:41",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "390104": [
        {
            "ioc_value": "159.65.246.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:42:29",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389873": [
        {
            "ioc_value": "68.183.200.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:58:18",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389866": [
        {
            "ioc_value": "138.68.227.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:57:13",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389865": [
        {
            "ioc_value": "165.227.219.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:56:32",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389864": [
        {
            "ioc_value": "165.232.154.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:55:44",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389861": [
        {
            "ioc_value": "143.198.110.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:53",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389860": [
        {
            "ioc_value": "178.128.171.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:15",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389853": [
        {
            "ioc_value": "165.227.23.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:53:10",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389850": [
        {
            "ioc_value": "161.35.137.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:52:19",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389847": [
        {
            "ioc_value": "64.227.0.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:51:26",
            "last_seen_utc": "2026-10-11 09:43:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389656": [
        {
            "ioc_value": "45.55.36.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-20 16:42:59",
            "last_seen_utc": "2026-10-11 09:43:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "384626": [
        {
            "ioc_value": "168.61.180.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-09 22:36:37",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "373668": [
        {
            "ioc_value": "bornometa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-10-11 09:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373671": [
        {
            "ioc_value": "jenevabaiden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373673": [
        {
            "ioc_value": "sbronm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "362296": [
        {
            "ioc_value": "101.34.182.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-29 22:33:30",
            "last_seen_utc": "2026-10-11 09:43:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332687": [
        {
            "ioc_value": "192.227.155.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:30:16",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332653": [
        {
            "ioc_value": "146.70.29.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:29:00",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "313943": [
        {
            "ioc_value": "107.172.219.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-22 22:25:42",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "299262": [
        {
            "ioc_value": "193.201.9.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 22:32:52",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SELECTEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "298501": [
        {
            "ioc_value": "citrixseruritys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-10-11 09:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "298505": [
        {
            "ioc_value": "milanvar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "295525": [
        {
            "ioc_value": "23.227.198.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 22:26:20",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295436": [
        {
            "ioc_value": "217.79.243.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 10:32:22",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295353": [
        {
            "ioc_value": "149.255.35.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-14 22:28:25",
            "last_seen_utc": "2026-10-11 09:43:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "294999": [
        {
            "ioc_value": "81.68.225.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-13 22:28:33",
            "last_seen_utc": "2026-10-11 09:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "292303": [
        {
            "ioc_value": "39.98.48.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-10 16:24:49",
            "last_seen_utc": "2026-10-11 09:42:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "291740": [
        {
            "ioc_value": "39.104.25.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-07 10:30:52",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "276593": [
        {
            "ioc_value": "77.83.36.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-16 10:42:30",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ISI-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "275144": [
        {
            "ioc_value": "101.32.204.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-13 10:06:28",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "252110": [
        {
            "ioc_value": "62.113.255.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-22 16:01:01",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TTM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "242948": [
        {
            "ioc_value": "107.173.89.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-04 17:48:48",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "240983": [
        {
            "ioc_value": "104.128.92.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-31 17:43:37",
            "last_seen_utc": "2026-10-11 09:43:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,IT7NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "238207": [
        {
            "ioc_value": "fivepointschiro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-27 09:58:20",
            "last_seen_utc": "2026-10-11 09:43:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/mojoesec/status/1453040284686770185",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "236436": [
        {
            "ioc_value": "111.230.196.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-22 12:07:15",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "233476": [
        {
            "ioc_value": "23.224.152.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-13 17:43:22",
            "last_seen_utc": "2026-10-11 09:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232821": [
        {
            "ioc_value": "139.198.183.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-11 23:27:10",
            "last_seen_utc": "2026-10-11 09:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YUNIFY-NET Yunify Technologies Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232263": [
        {
            "ioc_value": "121.37.255.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-09 23:36:53",
            "last_seen_utc": "2026-10-11 09:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "223357": [
        {
            "ioc_value": "47.95.207.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-09-18 17:39:24",
            "last_seen_utc": "2026-10-11 09:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ]
}