{
    "1871972": [
        {
            "ioc_value": "wag1cew7.josephmichaelnh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:19:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871971": [
        {
            "ioc_value": "tknlci.go-neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:15:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871970": [
        {
            "ioc_value": "qgcoxsq.eng--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:14:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871969": [
        {
            "ioc_value": "eng--sightfresh.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:13:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871968": [
        {
            "ioc_value": "go-neuroxen.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:12:30",
            "last_seen_utc": "2026-08-11 03:13:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871967": [
        {
            "ioc_value": "kuoquga.eng--neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:07:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871966": [
        {
            "ioc_value": "eng--neuroxen.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 03:05:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871965": [
        {
            "ioc_value": "180.76.53.183:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-11 03:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871964": [
        {
            "ioc_value": "gcobdr.get-thyrafemmebalance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 02:50:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871963": [
        {
            "ioc_value": "get-thyrafemmebalance.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 02:45:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871962": [
        {
            "ioc_value": "nlnnadg.en-us-thyrafemme-balance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 02:16:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871961": [
        {
            "ioc_value": "en-us-thyrafemme-balance.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 02:15:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871960": [
        {
            "ioc_value": "verif-key-code.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 02:08:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,ClickFix,ErrTraffic,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871957": [
        {
            "ioc_value": "shnsji.get-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 02:00:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871956": [
        {
            "ioc_value": "get-sightfresh.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:55:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871954": [
        {
            "ioc_value": "jrnix9p0.eng-us--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:36:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871953": [
        {
            "ioc_value": "svwuxca.en-us-energyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:26:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871952": [
        {
            "ioc_value": "en-us-energyrevolution.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:24:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871941": [
        {
            "ioc_value": "ae5ap687.healthfoodzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:16:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871938": [
        {
            "ioc_value": "wtdqug.get--ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:05:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871936": [
        {
            "ioc_value": "43.254.166.41:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 01:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871935": [
        {
            "ioc_value": "43.254.166.41:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-11 01:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871934": [
        {
            "ioc_value": "8.147.56.196:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-11 01:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871931": [
        {
            "ioc_value": "get--ignitra.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 01:04:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871930": [
        {
            "ioc_value": "qvmmaxk.en-us--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 00:36:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871929": [
        {
            "ioc_value": "dbfvnqy.en-us--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 00:31:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871928": [
        {
            "ioc_value": "en-us--sightfresh.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 00:29:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871926": [
        {
            "ioc_value": "nduzuc.get-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 00:14:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871925": [
        {
            "ioc_value": "get-goldalign.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-11 00:14:18",
            "last_seen_utc": "2026-08-11 00:15:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871924": [
        {
            "ioc_value": "43.254.166.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 23:46:52",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871923": [
        {
            "ioc_value": "update.qzkgpqn.kdns.fr",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 23:46:29",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871922": [
        {
            "ioc_value": "jrplawb.en-us--neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:43:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871921": [
        {
            "ioc_value": "en-us--neuroxen.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:41:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871918": [
        {
            "ioc_value": "https://goo.bercak4d.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 23:40:05",
            "last_seen_utc": "2026-08-11 03:26:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871919": [
        {
            "ioc_value": "goo.sm188blood.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 23:40:05",
            "last_seen_utc": "2026-08-11 03:25:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871920": [
        {
            "ioc_value": "https://goo.sm188blood.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 23:40:05",
            "last_seen_utc": "2026-08-11 03:25:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871917": [
        {
            "ioc_value": "goo.bercak4d.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 23:40:04",
            "last_seen_utc": "2026-08-11 03:26:10",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871916": [
        {
            "ioc_value": "ikhppmm.buy-ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:32:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871915": [
        {
            "ioc_value": "buy-ignitra.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:31:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871914": [
        {
            "ioc_value": "ccrcjzl.shop-mochalean.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:31:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871913": [
        {
            "ioc_value": "shop-mochalean.us!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:30:51",
            "last_seen_utc": "2026-08-10 23:31:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871912": [
        {
            "ioc_value": "mfkxos.getbraindefender.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:26:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871911": [
        {
            "ioc_value": "getbraindefender.us!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:23:28",
            "last_seen_utc": "2026-08-10 23:24:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871910": [
        {
            "ioc_value": "zs7rf4oz.havenchurchraleigh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:18:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871909": [
        {
            "ioc_value": "gs8istwl.en-usa-sugarmute.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:18:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871908": [
        {
            "ioc_value": "bkuseej.goldelign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:05:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871907": [
        {
            "ioc_value": "goldelign.com!s!",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 23:02:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871904": [
        {
            "ioc_value": "lydbvsp.shop-mochalean.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 22:35:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871903": [
        {
            "ioc_value": "shop-mochalean.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 22:34:41",
            "last_seen_utc": "2026-08-10 22:35:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871902": [
        {
            "ioc_value": "xgbkho.get-braindefender.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 22:34:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871901": [
        {
            "ioc_value": "get-braindefender.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 22:33:00",
            "last_seen_utc": "2026-08-10 22:33:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871900": [
        {
            "ioc_value": "nsfpfas.goldelign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 22:14:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871899": [
        {
            "ioc_value": "goldelign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 22:13:19",
            "last_seen_utc": "2026-08-10 23:03:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871898": [
        {
            "ioc_value": "vhdekj.en-web-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 21:47:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871896": [
        {
            "ioc_value": "en-web-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 21:42:28",
            "last_seen_utc": "2026-08-10 21:43:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871895": [
        {
            "ioc_value": "i0bx7ts6.en-en-en-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 21:25:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871894": [
        {
            "ioc_value": "jortbrc.goldaling.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 21:24:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871893": [
        {
            "ioc_value": "goldaling.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 21:22:49",
            "last_seen_utc": "2026-08-10 21:23:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871892": [
        {
            "ioc_value": "lvr1xtam.habbofutbol.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 21:14:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871890": [
        {
            "ioc_value": "134.122.200.217:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-10 21:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871891": [
        {
            "ioc_value": "89.125.244.131:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-10 21:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871889": [
        {
            "ioc_value": "192.252.179.24:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 21:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871887": [
        {
            "ioc_value": "jqiltw.enus-tinnitrol.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 20:52:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871886": [
        {
            "ioc_value": "enus-tinnitrol.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 20:52:00",
            "last_seen_utc": "2026-08-10 20:52:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871885": [
        {
            "ioc_value": "qoommbx.goldalin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 20:33:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871884": [
        {
            "ioc_value": "goldalin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 20:32:17",
            "last_seen_utc": "2026-08-10 20:33:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871883": [
        {
            "ioc_value": "192.252.185.78:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 20:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871881": [
        {
            "ioc_value": "192.252.185.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 20:05:05",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871882": [
        {
            "ioc_value": "192.252.185.78:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 20:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871880": [
        {
            "ioc_value": "wnplhn.enus-thyrafemmebalance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 20:02:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871879": [
        {
            "ioc_value": "enus-thyrafemmebalance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 20:01:28",
            "last_seen_utc": "2026-08-10 20:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871878": [
        {
            "ioc_value": "91.92.42.22:6767",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:46:44",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871877": [
        {
            "ioc_value": "85.137.252.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:46:36",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871876": [
        {
            "ioc_value": "64.89.160.127:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:46:25",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871875": [
        {
            "ioc_value": "5.133.102.33:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 19:46:16",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871874": [
        {
            "ioc_value": "46.151.182.113:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 19:46:12",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871873": [
        {
            "ioc_value": "45.88.91.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:46:10",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871872": [
        {
            "ioc_value": "38.54.45.183:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-10 19:45:52",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871871": [
        {
            "ioc_value": "37.244.251.138:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-10 19:45:48",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871870": [
        {
            "ioc_value": "31.76.125.2:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:45:45",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871869": [
        {
            "ioc_value": "216.250.254.245:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:45:31",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871868": [
        {
            "ioc_value": "186.168.97.172:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-10 19:44:23",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871867": [
        {
            "ioc_value": "181.215.49.119:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:44:14",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871865": [
        {
            "ioc_value": "172.81.132.75:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:44:05",
            "last_seen_utc": "2026-08-11 02:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871866": [
        {
            "ioc_value": "172.81.132.75:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:44:05",
            "last_seen_utc": "2026-08-11 02:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871864": [
        {
            "ioc_value": "151.241.99.168:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:43:40",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871863": [
        {
            "ioc_value": "118.99.88.240:10549",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871862": [
        {
            "ioc_value": "104.249.10.87:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 19:43:13",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871861": [
        {
            "ioc_value": "103.213.248.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 19:43:06",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871860": [
        {
            "ioc_value": "nksdosz.goldalignn.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 19:42:12",
            "last_seen_utc": "2026-08-10 19:42:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871859": [
        {
            "ioc_value": "goldalaign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 19:41:10",
            "last_seen_utc": "2026-08-10 19:41:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871858": [
        {
            "ioc_value": "http://shkpiva.shop:5627/comments",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 19:35:35",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b431762c4d8a0a25d9a210bbfdfa302c2be3dca39121cf10ede9575332b63ffc/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871857": [
        {
            "ioc_value": "http://beljaro.shop:2536/images",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 19:35:31",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b431762c4d8a0a25d9a210bbfdfa302c2be3dca39121cf10ede9575332b63ffc/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871799": [
        {
            "ioc_value": "belorks.xyz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 19:31:02",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://www.clickfixed.uk/intel/7298",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "ClickFixer"
        }
    ],
    "1871806": [
        {
            "ioc_value": "38.97.63.243:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-08-10 19:31:02",
            "last_seen_utc": "2026-08-10 23:48:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871835": [
        {
            "ioc_value": "https://seversin.lol/mods/api/log-download",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 19:31:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871836": [
        {
            "ioc_value": "https://seversin.lol/ws",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 19:31:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871837": [
        {
            "ioc_value": "https://seversin.lol/?p=",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 19:31:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871838": [
        {
            "ioc_value": "https://seversin.lol/get/config",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 19:31:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871840": [
        {
            "ioc_value": "seversin.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 19:31:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871839": [
        {
            "ioc_value": "https://seversin.lol/babayla/zor/yarisirlar/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 19:30:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871842": [
        {
            "ioc_value": "http://61.52.157.83:44657/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 19:30:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/61.52.157.83",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871843": [
        {
            "ioc_value": "http://153.117.14.15:48887/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 19:30:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.14.15",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871856": [
        {
            "ioc_value": "206.189.81.41:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-10 19:30:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871855": [
        {
            "ioc_value": "59qxatd0.gtacauto.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 19:16:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871854": [
        {
            "ioc_value": "fgauki.en-us-thyrafemme-balance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 19:12:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871853": [
        {
            "ioc_value": "en-us-thyrafemme-balance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 19:10:47",
            "last_seen_utc": "2026-08-11 02:15:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871852": [
        {
            "ioc_value": "192.252.179.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 19:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871851": [
        {
            "ioc_value": "192.252.179.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 19:05:07",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871850": [
        {
            "ioc_value": "http://tokjoza.shop:5200/images",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 19:00:59",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7bd899846f7782027431f3a4f582b166f6944bbc4fdbd86aadd78c248c57f485/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871849": [
        {
            "ioc_value": "http://shkpiva.shop:5627/reviews",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 19:00:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7bd899846f7782027431f3a4f582b166f6944bbc4fdbd86aadd78c248c57f485/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871848": [
        {
            "ioc_value": "http://beljaro.shop:2536/projects",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 19:00:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/7bd899846f7782027431f3a4f582b166f6944bbc4fdbd86aadd78c248c57f485/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871847": [
        {
            "ioc_value": "hmskuzk.get-thyrafemmebalance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 18:51:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871846": [
        {
            "ioc_value": "get-thyrafemmebalance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 18:50:08",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871845": [
        {
            "ioc_value": "vrswff.en-us-theslimsplitsmethod.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 18:22:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871844": [
        {
            "ioc_value": "en-us-theslimsplitsmethod.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 18:20:18",
            "last_seen_utc": "2026-08-10 18:20:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871841": [
        {
            "ioc_value": "28jk0aeb.eng-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 18:17:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871834": [
        {
            "ioc_value": "jmnttbq.getsightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 18:05:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871833": [
        {
            "ioc_value": "http://tokjoza.shop:5200/accounts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 18:01:04",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/721e28946f79f65e9722d27fdb6fb384a3fb747c82b4c8c2f9dffc0fdc6c0a49/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871832": [
        {
            "ioc_value": "http://shkpiva.shop:5627/videos",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 18:01:01",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/721e28946f79f65e9722d27fdb6fb384a3fb747c82b4c8c2f9dffc0fdc6c0a49/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871831": [
        {
            "ioc_value": "http://beljaro.shop:2536/contacts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 18:00:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/721e28946f79f65e9722d27fdb6fb384a3fb747c82b4c8c2f9dffc0fdc6c0a49/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871830": [
        {
            "ioc_value": "getsightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:59:41",
            "last_seen_utc": "2026-08-10 18:00:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871829": [
        {
            "ioc_value": "46.246.4.9:7044",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vjw0rm",
            "malware_alias": null,
            "malware_printable": "Vjw0rm",
            "first_seen_utc": "2026-08-10 17:45:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vjw0rm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871828": [
        {
            "ioc_value": "http://wagosinga.ydns.eu:7044/is-ready",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.houdini",
            "malware_alias": "Hworm,Jenxcus,Kognito,Njw0rm,WSHRAT,dinihou,dunihi",
            "malware_printable": "Houdini",
            "first_seen_utc": "2026-08-10 17:45:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,WSHRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871827": [
        {
            "ioc_value": "http://tokjoza.shop:5200/tags",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 17:40:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/32c100b984e2a26d588fafc648dcdd7694788d0c18af15704e3601ffc001f334/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871826": [
        {
            "ioc_value": "http://none/tokens",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 17:40:38",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/32c100b984e2a26d588fafc648dcdd7694788d0c18af15704e3601ffc001f334/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871825": [
        {
            "ioc_value": "http://beljaro.shop:2536/posts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 17:40:36",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/32c100b984e2a26d588fafc648dcdd7694788d0c18af15704e3601ffc001f334/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871824": [
        {
            "ioc_value": "eolins.en-us-theenergyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:39:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871823": [
        {
            "ioc_value": "en-us-theenergyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:35:03",
            "last_seen_utc": "2026-08-10 17:35:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871822": [
        {
            "ioc_value": "ergo-up.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:28:22",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871821": [
        {
            "ioc_value": "https://its.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 17:20:05",
            "last_seen_utc": "2026-08-10 23:26:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871820": [
        {
            "ioc_value": "its.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 17:20:04",
            "last_seen_utc": "2026-08-10 23:26:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871819": [
        {
            "ioc_value": "phhqqp5d.grannygshemporium.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:16:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871818": [
        {
            "ioc_value": "aoy7vij2.foodpapajobs.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:16:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871817": [
        {
            "ioc_value": "https://its.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 17:15:05",
            "last_seen_utc": "2026-08-10 23:25:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871816": [
        {
            "ioc_value": "its.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 17:15:04",
            "last_seen_utc": "2026-08-10 23:25:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871815": [
        {
            "ioc_value": "ozfttik.get-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:10:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871814": [
        {
            "ioc_value": "get-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 17:09:13",
            "last_seen_utc": "2026-08-11 01:55:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871813": [
        {
            "ioc_value": "154.12.86.154:8002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 17:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871812": [
        {
            "ioc_value": "ynbfqi.enus-synaptigen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:45:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871811": [
        {
            "ioc_value": "enus-synaptigen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:43:48",
            "last_seen_utc": "2026-08-10 16:44:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871810": [
        {
            "ioc_value": "5.223.80.130:318",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.nanocore",
            "malware_alias": "Nancrat,NanoCore",
            "malware_printable": "Nanocore RAT",
            "first_seen_utc": "2026-08-10 16:40:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "NanoCore,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871809": [
        {
            "ioc_value": "bypraqr.get--ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:22:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871808": [
        {
            "ioc_value": "get--ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:19:38",
            "last_seen_utc": "2026-08-11 01:05:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871807": [
        {
            "ioc_value": "getignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:18:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871805": [
        {
            "ioc_value": "en-us--sleeplean.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:11:53",
            "last_seen_utc": "2026-08-10 16:11:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871804": [
        {
            "ioc_value": "en-ussleeplean.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:11:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871803": [
        {
            "ioc_value": "en-us-sleep-leans.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 16:04:46",
            "last_seen_utc": "2026-08-10 16:05:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871802": [
        {
            "ioc_value": "fhuyul.en-us-superbrain.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:53:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871801": [
        {
            "ioc_value": "hlzhpm.en-us-superbrain.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:45:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871800": [
        {
            "ioc_value": "en-us-superbrain.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:44:11",
            "last_seen_utc": "2026-08-10 15:53:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871798": [
        {
            "ioc_value": "31.59.118.77:7004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 15:25:51",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/30f8fdb26e5ef75f382fd927a35e00ea8accd504e677058b7fd28e6a73553d40/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871797": [
        {
            "ioc_value": "155.103.71.203:2233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 15:25:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c803ce174f0688c83f94db7001b99d103b5d027be7d0d230494a5dfdb88c9619/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871796": [
        {
            "ioc_value": "oceanking.noip.at",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:25:32",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bab65bff384cc974f7b0dc36080ab51841745997f9e7da4888445ce618ac3482/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871795": [
        {
            "ioc_value": "dunday.mytunnel.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:25:31",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bab65bff384cc974f7b0dc36080ab51841745997f9e7da4888445ce618ac3482/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871794": [
        {
            "ioc_value": "87.120.244.219:19601",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:20:49",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bf24bb51af4d6c922bcb3eb46a712fef9cf3ed76822ebde5669a62673bf1d300/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871793": [
        {
            "ioc_value": "anilmut.ydns.eu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:20:33",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/303a507698ff9aab2d8df60f2ed2080e14204f3083bea4d5d01705a54cf6fea8/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871792": [
        {
            "ioc_value": "cgfmqtn.en-us-sightfrresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:17:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871791": [
        {
            "ioc_value": "en-us-sightfrresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:14:15",
            "last_seen_utc": "2026-08-10 15:14:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871790": [
        {
            "ioc_value": "fmtt8q1j.fungame777.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:14:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871789": [
        {
            "ioc_value": "xndjbjo.enus-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:09:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871788": [
        {
            "ioc_value": "enus-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:09:05",
            "last_seen_utc": "2026-08-10 15:10:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871787": [
        {
            "ioc_value": "155.254.98.57:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 15:05:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/248d6fd4d064a4ced3a75ee493a43afb2a909d3c14726150685fb26147fc8d3b/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871786": [
        {
            "ioc_value": "155.103.71.88:3456",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 15:05:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5a83f8a2973445c7e801d8b470851a4fa6dfc51c776f8233c727c7fab9281fee/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871785": [
        {
            "ioc_value": "www.xmmtbxbackup2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:05:35",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4da2425b6d3677ff80e52dd880a6f718257ad3c15deb565cd947b6f3aa05a9eb/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871782": [
        {
            "ioc_value": "www.xmmtbx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:05:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4da2425b6d3677ff80e52dd880a6f718257ad3c15deb565cd947b6f3aa05a9eb/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871783": [
        {
            "ioc_value": "www.xmmtbxbackup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:05:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4da2425b6d3677ff80e52dd880a6f718257ad3c15deb565cd947b6f3aa05a9eb/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871784": [
        {
            "ioc_value": "www.xmmtbxbackup1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 15:05:34",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4da2425b6d3677ff80e52dd880a6f718257ad3c15deb565cd947b6f3aa05a9eb/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871781": [
        {
            "ioc_value": "49.232.108.35:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-10 15:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871779": [
        {
            "ioc_value": "141.94.121.162:4242",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871780": [
        {
            "ioc_value": "154.12.32.114:1141",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871778": [
        {
            "ioc_value": "2.50.170.49:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 15:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871777": [
        {
            "ioc_value": "bewegungszentrum-hochdorf.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:01:19",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871776": [
        {
            "ioc_value": "okqhiof.en-us--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 15:01:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871775": [
        {
            "ioc_value": "tvalui.en-us-sugermute.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:54:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871774": [
        {
            "ioc_value": "en-us-sugermute.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:53:35",
            "last_seen_utc": "2026-08-10 14:54:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871773": [
        {
            "ioc_value": "217.60.195.236:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:45:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871772": [
        {
            "ioc_value": "nslabqu.en-us--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:41:15",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871771": [
        {
            "ioc_value": "5.230.201.75:8996",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-08-10 14:39:30",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bc16cf19075de6200a10d31a5f8775461c6d98c0d2f41d2b59c1ed28659b62c3/",
            "tags": "PureLogsStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871770": [
        {
            "ioc_value": "87.120.244.219:17598",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:35:46",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/fc48b40be3b232ad4cdd5630d857cfe50415fe05b6677f74510cb6af109328c0/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871769": [
        {
            "ioc_value": "sysupdate.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 14:32:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ca8f173b7f0f76ffef2672776582a05434138b4e0fcbd738157268cc54d32231/",
            "tags": "MeshAgent,RMM",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871768": [
        {
            "ioc_value": "191.215.37.40:5173",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.overlord",
            "malware_alias": null,
            "malware_printable": "Overlord RAT",
            "first_seen_utc": "2026-08-10 14:27:29",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bb024a4c3e301b740e986aecf768d0d7947a75b33dccde6e52baf15c0b0a59fc/",
            "tags": "Overlord,OverlordRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871767": [
        {
            "ioc_value": "clflwpz.en-us--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:27:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871766": [
        {
            "ioc_value": "161.97.162.13:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:25:30",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3ccb005c80531d21f8cfdf7823f55b16a55fc83a8b05935224b89f3aaa4e6320/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871765": [
        {
            "ioc_value": "107.172.134.28:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 14:25:29",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bf8d6c2f8125dc85a5a830c5e940951441c92823db6793794008301ba6f3f5d6/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871764": [
        {
            "ioc_value": "en-us--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:24:28",
            "last_seen_utc": "2026-08-11 00:34:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871763": [
        {
            "ioc_value": "en-ussightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:24:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871631": [
        {
            "ioc_value": "64.227.68.158:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:14",
            "last_seen_utc": "2026-08-11 03:29:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871632": [
        {
            "ioc_value": "165.22.197.20:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:14",
            "last_seen_utc": "2026-08-11 03:29:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871633": [
        {
            "ioc_value": "165.232.87.245:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:13",
            "last_seen_utc": "2026-08-11 03:29:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871634": [
        {
            "ioc_value": "178.62.229.223:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:13",
            "last_seen_utc": "2026-08-11 03:30:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871636": [
        {
            "ioc_value": "159.223.209.14:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:12",
            "last_seen_utc": "2026-08-11 03:29:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871638": [
        {
            "ioc_value": "161.35.155.251:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:12",
            "last_seen_utc": "2026-08-11 03:27:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871637": [
        {
            "ioc_value": "167.71.67.197:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:11",
            "last_seen_utc": "2026-08-11 03:30:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871639": [
        {
            "ioc_value": "178.62.230.102:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:11",
            "last_seen_utc": "2026-08-11 03:29:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871640": [
        {
            "ioc_value": "142.93.139.221:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-10 14:24:10",
            "last_seen_utc": "2026-08-11 03:25:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871648": [
        {
            "ioc_value": "belorks.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:24:10",
            "last_seen_utc": "2026-08-10 11:15:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1871717": [
        {
            "ioc_value": "38.97.63.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-08-10 14:24:09",
            "last_seen_utc": "2026-08-10 15:11:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871718": [
        {
            "ioc_value": "http://103.174.243.219:35630/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 14:24:09",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/103.174.243.219",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871719": [
        {
            "ioc_value": "http://120.229.79.252:33575/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 14:24:09",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/120.229.79.252",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871720": [
        {
            "ioc_value": "http://72.255.32.86:39014/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 14:24:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/72.255.32.86",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871721": [
        {
            "ioc_value": "http://175.107.233.255:52927/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 14:24:08",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/175.107.233.255",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871724": [
        {
            "ioc_value": "ebnlinfengv6l2ilx.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-10 14:24:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f5c235bf56a9c15afb65f83f437678cd6fac7e23b9a850b7806d395f4b778948/",
            "tags": null,
            "anonymous": 0,
            "reporter": "emmanualopsecgo"
        }
    ],
    "1871734": [
        {
            "ioc_value": "http://20.214.2.18/receive.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-08-10 14:24:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/b979f185-839a-4b4d-ae31-6dbb84a18675",
            "tags": "discord,generic,nodejs,nyxstealer,stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871728": [
        {
            "ioc_value": "161.35.48.40:12345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-10 14:24:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871761": [
        {
            "ioc_value": "185.242.4.122:37393",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:20:26",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/279e14ad7bad135f7b63e17c355c969116c2db600967061bbab107f66d62dbb6/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871762": [
        {
            "ioc_value": "209.127.35.195:3533",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:20:26",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f66bd3ba1b2b9190f924031ebb2346338df2e26c189850ee3237ea80adc898eb/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871760": [
        {
            "ioc_value": "109.248.148.247:32734",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:20:24",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/eb2cd2c52a03b20d87ea129eb09842e8ece28bf7476a61d3fefc229b0e8622ec/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871759": [
        {
            "ioc_value": "109.248.151.124:7575",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 14:15:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/428e478e4fd72979677f7fc4f568a2fd05a811cb3ff555a4bd068226e86b012f/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871758": [
        {
            "ioc_value": "86.106.84.151:37393",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:10:46",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c961a6099fe726be83ed564f937b3f259cf6023451f09d6f22536ed4fba18011/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871757": [
        {
            "ioc_value": "31.13.190.82:37393",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:10:45",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/5d13cfc9ec95b80219e759f945661eb22e4781df28a181474a040dc72068562b/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871756": [
        {
            "ioc_value": "kindjurt.myddns.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 14:10:37",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f6bcc2de6becba2ea62a6766184c5003d379fc70c88dfdb53b0c3b184a81ac94/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871755": [
        {
            "ioc_value": "kwoeju.en-us-slimsplitsmethod.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:05:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871752": [
        {
            "ioc_value": "101.35.129.174:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871753": [
        {
            "ioc_value": "34.92.128.98:50050",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871754": [
        {
            "ioc_value": "108.165.147.244:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 14:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871751": [
        {
            "ioc_value": "101.35.129.174:6379",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871750": [
        {
            "ioc_value": "en-us-slimsplitsmethod.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 14:03:11",
            "last_seen_utc": "2026-08-10 14:03:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871749": [
        {
            "ioc_value": "cpvmfg.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:55:39",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871748": [
        {
            "ioc_value": "37.120.146.146:37393",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 13:50:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08e9ee91c55772b2c30f2ca6d26b9960000f3b08d08bf878d5d95045c93fa7c8/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871747": [
        {
            "ioc_value": "104.249.130.248:5960",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 13:50:43",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6b555912da38f884965345b7012569f6ad38292fb073157b4ff4fac15a00cc26/",
            "tags": "xworm",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871746": [
        {
            "ioc_value": "onboard.radiantfluxstudio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 13:45:42",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8dba8da0a8c596b4f3a886f95c57bdb6d8b046ee356d3c52555c3bc3fb0cd114/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871745": [
        {
            "ioc_value": "foxybridge.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:45:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871744": [
        {
            "ioc_value": "46.183.218.151:37393",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 13:40:44",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/0c3a63f8f91965db6755ea623fe109ee291dbba63dda3022b1a22a9640bccee9/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871743": [
        {
            "ioc_value": "185.14.92.102:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 13:40:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871742": [
        {
            "ioc_value": "llasvij.en-us-odizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:38:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871741": [
        {
            "ioc_value": "196.251.121.163:14555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 13:35:39",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/132334806bc8620a8900f061ba535b049b2c756a3987c0a8a3bd58a82bf45579/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871740": [
        {
            "ioc_value": "en-us-odizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:33:45",
            "last_seen_utc": "2026-08-10 14:55:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871739": [
        {
            "ioc_value": "go78tteu.eng-nitrilean.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:17:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871738": [
        {
            "ioc_value": "nyerki.en-us-slimsplits.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:15:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871737": [
        {
            "ioc_value": "en-us-slimsplits.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:12:40",
            "last_seen_utc": "2026-08-10 13:12:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871736": [
        {
            "ioc_value": "0rwgfz6h.finkfamilyautomotive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:11:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871735": [
        {
            "ioc_value": "weqtrjme.eng-usa-digestistart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 13:07:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871733": [
        {
            "ioc_value": "101.35.129.174:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 13:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871732": [
        {
            "ioc_value": "101.35.129.174:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871731": [
        {
            "ioc_value": "101.35.129.174:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871729": [
        {
            "ioc_value": "217.60.241.170:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871730": [
        {
            "ioc_value": "154.221.25.38:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871727": [
        {
            "ioc_value": "czrsixg.en-us--neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 12:44:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871726": [
        {
            "ioc_value": "en-us--neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 12:43:49",
            "last_seen_utc": "2026-08-10 23:42:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871725": [
        {
            "ioc_value": "en-usneuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 12:43:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871723": [
        {
            "ioc_value": "cqyxny.enus-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 12:23:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871722": [
        {
            "ioc_value": "enus-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 12:22:08",
            "last_seen_utc": "2026-08-10 12:23:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871716": [
        {
            "ioc_value": "pyfcdqnpvnbwagbyxe.en-usa-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 12:06:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0xa770,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871715": [
        {
            "ioc_value": "ealceem.enus-ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:54:20",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871714": [
        {
            "ioc_value": "enus-ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:52:29",
            "last_seen_utc": "2026-08-10 11:53:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871711": [
        {
            "ioc_value": "de71cf8817c3e91c8a00c22198bb36d6655f00e32741098ae5d81ec09ea69918",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "elf.kuiper",
            "malware_alias": null,
            "malware_printable": "Kuiper",
            "first_seen_utc": "2026-08-10 11:49:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871712": [
        {
            "ioc_value": "5df985e256e32dd57aaac1bad79672fbb44788ea",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "elf.kuiper",
            "malware_alias": null,
            "malware_printable": "Kuiper",
            "first_seen_utc": "2026-08-10 11:49:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871713": [
        {
            "ioc_value": "662d653f550544643f67c3891ff2cf2c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "elf.kuiper",
            "malware_alias": null,
            "malware_printable": "Kuiper",
            "first_seen_utc": "2026-08-10 11:49:11",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871709": [
        {
            "ioc_value": "1441b32780ec0e76d09af693f62819c2d1ae8125",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-10 11:49:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871710": [
        {
            "ioc_value": "33d103a950e97fb4c0f28d8cff985ba6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-10 11:49:10",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871707": [
        {
            "ioc_value": "0e260f328a81040da84f79bb21d54953",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 11:49:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871708": [
        {
            "ioc_value": "904bb06ad9ad3c8e4aa980b96cbecad85c14bd994af013d77121723c85a5e1a9",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-10 11:49:09",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871706": [
        {
            "ioc_value": "965974f7bb6bd5c71da7d0ae843ea3f84229b74c",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 11:49:08",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871702": [
        {
            "ioc_value": "2a167fbe58a9d874dda8798e9b0d773d9316a217256a7e3f1d0c5e3e26f9f03a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 11:49:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871703": [
        {
            "ioc_value": "666974fd5ab2ab200c8c87e1945708c9e4f2e76e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 11:49:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871704": [
        {
            "ioc_value": "325dd213f9a6f78e41cad30c49e0a178",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 11:49:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871705": [
        {
            "ioc_value": "da9442ac1174544216a00fb1792f7ee019cb708e47cd5948a9632e24285b36cb",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 11:49:07",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871699": [
        {
            "ioc_value": "c829ecdfad04daba449fb93106f176c5fd065f3642b70cc46ab4285246a3057d",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.creal_stealer",
            "malware_alias": null,
            "malware_printable": "Creal Stealer",
            "first_seen_utc": "2026-08-10 11:49:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871700": [
        {
            "ioc_value": "40bb4c848b9e8843d48884ded074af0dc183778d",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.creal_stealer",
            "malware_alias": null,
            "malware_printable": "Creal Stealer",
            "first_seen_utc": "2026-08-10 11:49:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871701": [
        {
            "ioc_value": "0bc755a061e932971b5e642b99adda04",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.creal_stealer",
            "malware_alias": null,
            "malware_printable": "Creal Stealer",
            "first_seen_utc": "2026-08-10 11:49:06",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871697": [
        {
            "ioc_value": "9b490baf8909538616aded33ffa0502f8a6fa085",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:49:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871698": [
        {
            "ioc_value": "a02aa86b025c34615a99437e118128fe",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:49:05",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871695": [
        {
            "ioc_value": "1b00808e8d58b136cd389361d01eb377",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-08-10 11:49:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871696": [
        {
            "ioc_value": "bbb3837bc8706b87668877a86fcda6a69ace99739e19caa744bef624570a7c0a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:49:04",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871693": [
        {
            "ioc_value": "90b2ceb05b34ed6012d20b547cec83a2dacbe56659eb4479150f30015172c3c2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-08-10 11:49:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871694": [
        {
            "ioc_value": "3692fc83c64796ce846099f9dc651a9b2140c10e",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-08-10 11:49:03",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871690": [
        {
            "ioc_value": "5d8353255bc5b09aaed218f2d6f016ceda78354cfb1a3f0d36d939d142f3a8f2",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:49:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871691": [
        {
            "ioc_value": "673a985979c3381c4b1b5103816a0a2a11f29bee",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:49:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871692": [
        {
            "ioc_value": "59e90d4e4072484541636b873c35a4a6",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:49:01",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871689": [
        {
            "ioc_value": "092821e77feade246a230168b2c0b775",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 11:49:00",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871687": [
        {
            "ioc_value": "b752cd26bfd88495e011ca4ace567f6715d1323bab0803d47b2736cfbc5db955",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 11:48:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871688": [
        {
            "ioc_value": "5fcb20277dab30f4ae6a46f9596d68d2cea74609",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 11:48:59",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871685": [
        {
            "ioc_value": "4c34f12dbee3457a9c1cf5185f59fc56084de8b8",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-10 11:48:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871686": [
        {
            "ioc_value": "2e4aa86a1df193c715970aee3096bf3a",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-10 11:48:58",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871682": [
        {
            "ioc_value": "2f7c74580c7031ba7d9ad89771032eca0ab61758",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:48:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871683": [
        {
            "ioc_value": "b24376060623dd8dabec2c3dd423361c",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:48:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871684": [
        {
            "ioc_value": "843b927de18b16ef40abb48067b6be80e4c63a9e9600342ca672bc75e84e7a48",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-10 11:48:57",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871679": [
        {
            "ioc_value": "b267d67a00e870fe7f6b2b595842231ddace2657",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:48:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871680": [
        {
            "ioc_value": "48d66a8f0f2a7d144cfa1f6b7a006c69",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:48:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871681": [
        {
            "ioc_value": "8e5e251d971957c982721ef54328000815d80c744f184fac3bb1afd64dd3624a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:48:56",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871677": [
        {
            "ioc_value": "f466e3112ffdfa965f4457c98dee5b92",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871678": [
        {
            "ioc_value": "1d60903c4cf77503ae2ccbc0e1f33e455033bca93d1a289531df7e1a166a5449",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:48:55",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871676": [
        {
            "ioc_value": "55f6b5e510fe2149eb713cce3aa68ec07d313c12",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:54",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871675": [
        {
            "ioc_value": "fd7cee5a13218f6d00b40e85579c6f4b4f06d5432b9fb785b0b81f8547c197f4",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:53",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871673": [
        {
            "ioc_value": "eb63f8a9af89d85b71ca649ed826c4244aa81e39",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871674": [
        {
            "ioc_value": "ae9893c7a60b298f3f45b85726e09a98",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:52",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871670": [
        {
            "ioc_value": "6c8ee646afb6b19ade6af5333c52c5263103f949",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871671": [
        {
            "ioc_value": "2be02d3def1b116c668cc84e628e2065",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871672": [
        {
            "ioc_value": "24d5d3e5095d9bd866d657c646d5c4035e64315c7ba3c17b230415f0bef8c0d3",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:51",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871667": [
        {
            "ioc_value": "2ac9f75fc9bc14e8f57e319630c3f9dde3a814f5",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871668": [
        {
            "ioc_value": "a65f533d10703afcd9cc1210ca559b75",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871669": [
        {
            "ioc_value": "45c985d787b9f8730c4b05555f8ecf28f9c58f0948c5180108ca185441ab145a",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:50",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871666": [
        {
            "ioc_value": "ee8bd9222c943d35f0702143c7606aef6a62b229ffc109a468537322e917a9e1",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.netwire",
            "malware_alias": "NetWeird,NetWire,Recam",
            "malware_printable": "NetWire RC",
            "first_seen_utc": "2026-08-10 11:48:49",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871665": [
        {
            "ioc_value": "fdb6448a3ac57e511a53cda07945be8f",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-10 11:48:48",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871662": [
        {
            "ioc_value": "893cf55eb5c958896580854b7f5c44e1",
            "ioc_type": "md5_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:48:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871663": [
        {
            "ioc_value": "f02eb5040f50f5bdade4c2a2114ec43c33bdf4a7fd9051f9f7d411eb50b1474e",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-10 11:48:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871664": [
        {
            "ioc_value": "35170d38f2089910e6dc71ea9a2fd202f6dd2736",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "py.venus_stealer",
            "malware_alias": null,
            "malware_printable": "Venus Stealer",
            "first_seen_utc": "2026-08-10 11:48:47",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871660": [
        {
            "ioc_value": "a6a6674d13230442f10b0b6663a5e659f9d3a072b8e575fd332baa5ff685a1d6",
            "ioc_type": "sha256_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:48:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871661": [
        {
            "ioc_value": "0c20fb53da56369ffb8c90706b8d1c05e76fc3e0",
            "ioc_type": "sha1_hash",
            "threat_type": "payload",
            "malware": "win.formbook",
            "malware_alias": "win.xloader",
            "malware_printable": "Formbook",
            "first_seen_utc": "2026-08-10 11:48:46",
            "last_seen_utc": null,
            "confidence_level": 95,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "Grim"
        }
    ],
    "1871659": [
        {
            "ioc_value": "123.207.203.20:55501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 11:47:37",
            "last_seen_utc": "2026-08-11 02:47:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871658": [
        {
            "ioc_value": "117.24.4.112:4521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 11:47:33",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871657": [
        {
            "ioc_value": "bztmkx.en-us-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:33:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871656": [
        {
            "ioc_value": "en-us-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:31:36",
            "last_seen_utc": "2026-08-10 11:32:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871655": [
        {
            "ioc_value": "enus-sleeplean.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:22:20",
            "last_seen_utc": "2026-08-10 11:23:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871653": [
        {
            "ioc_value": "poc.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:15:06",
            "last_seen_utc": "2026-08-10 16:26:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871654": [
        {
            "ioc_value": "https://poc.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:15:06",
            "last_seen_utc": "2026-08-10 16:26:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871651": [
        {
            "ioc_value": "poc.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:15:05",
            "last_seen_utc": "2026-08-10 16:26:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871652": [
        {
            "ioc_value": "https://poc.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 11:15:05",
            "last_seen_utc": "2026-08-10 16:26:20",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871650": [
        {
            "ioc_value": "78sgh99h.en-us-energyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:12:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871649": [
        {
            "ioc_value": "nynashanti.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:05:38",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871647": [
        {
            "ioc_value": "skrfpet.en-us-ignitraa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:02:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871646": [
        {
            "ioc_value": "en-us-ignitraa.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 11:01:55",
            "last_seen_utc": "2026-08-10 11:02:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871645": [
        {
            "ioc_value": "http://tokjoza.shop:5200/webhooks",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 10:50:46",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f02eb5040f50f5bdade4c2a2114ec43c33bdf4a7fd9051f9f7d411eb50b1474e/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871644": [
        {
            "ioc_value": "http://none/profiles",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 10:50:41",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f02eb5040f50f5bdade4c2a2114ec43c33bdf4a7fd9051f9f7d411eb50b1474e/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871643": [
        {
            "ioc_value": "http://beljaro.shop:2536/invoices",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 10:50:39",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f02eb5040f50f5bdade4c2a2114ec43c33bdf4a7fd9051f9f7d411eb50b1474e/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871642": [
        {
            "ioc_value": "cahnzr.prosta--vive.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 10:32:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871641": [
        {
            "ioc_value": "zfeodhb.en-us-goldaligns.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 10:25:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871635": [
        {
            "ioc_value": "en-us-goldaligns.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 10:23:34",
            "last_seen_utc": "2026-08-10 10:24:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871630": [
        {
            "ioc_value": "http://tokjoza.shop:5200/attachments",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 10:00:56",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/843b927de18b16ef40abb48067b6be80e4c63a9e9600342ca672bc75e84e7a48/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871629": [
        {
            "ioc_value": "http://shkpiva.shop:5627/tokens",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 10:00:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/843b927de18b16ef40abb48067b6be80e4c63a9e9600342ca672bc75e84e7a48/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871628": [
        {
            "ioc_value": "http://beljaro.shop:2536/accounts",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 10:00:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/843b927de18b16ef40abb48067b6be80e4c63a9e9600342ca672bc75e84e7a48/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871627": [
        {
            "ioc_value": "authorljmatin.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 10:00:37",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871626": [
        {
            "ioc_value": "98.191.191.44:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-10 09:46:58",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871625": [
        {
            "ioc_value": "91.92.42.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 09:46:52",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871624": [
        {
            "ioc_value": "91.92.34.73:43283",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 09:46:51",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871623": [
        {
            "ioc_value": "77.237.97.58:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-10 09:46:36",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871622": [
        {
            "ioc_value": "31.77.195.32:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 09:45:53",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871621": [
        {
            "ioc_value": "209.99.190.23:56014",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 09:44:52",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871620": [
        {
            "ioc_value": "167.233.161.42:3287",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-10 09:43:58",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871619": [
        {
            "ioc_value": "159.203.69.210:8401",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 09:43:52",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871618": [
        {
            "ioc_value": "149.28.121.179:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-10 09:43:38",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871617": [
        {
            "ioc_value": "104.239.66.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 09:43:10",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871616": [
        {
            "ioc_value": "uhfazu.tiroalpaloes.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:40:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871608": [
        {
            "ioc_value": "volrko.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:36:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1871578": [
        {
            "ioc_value": "testmyopinion.live",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 09:36:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://www.clickfixed.uk/intel/7252",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "ClickFixer"
        }
    ],
    "1871615": [
        {
            "ioc_value": "ronaldbeck.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 09:35:39",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ee9918abc39d7d0b46c5cf7891f5b845d0ae5acc0e88f22ecd6ad19099260651/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871614": [
        {
            "ioc_value": "beckronald.duckdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 09:35:38",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/ee9918abc39d7d0b46c5cf7891f5b845d0ae5acc0e88f22ecd6ad19099260651/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871613": [
        {
            "ioc_value": "ftp.holzbrenzii.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.agent_tesla",
            "malware_alias": "AgenTesla,AgentTesla,Negasteal",
            "malware_printable": "Agent Tesla",
            "first_seen_utc": "2026-08-10 09:34:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e9855bdf3f45a2ed0148a1f6714f6ce081f4da526aeb044d2e58ee394e62078b/",
            "tags": "AgentTesl",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871612": [
        {
            "ioc_value": "otp.vagrancyvirus.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-10 09:33:33",
            "last_seen_utc": "2026-08-10 09:33:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/cd598cea811d8f73ca7afffa40e5963be9a82e01bad8ffcebb104b475c091faa/",
            "tags": "ACRStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871611": [
        {
            "ioc_value": "ucooyac.enus-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:33:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871610": [
        {
            "ioc_value": "volrko.pro",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-10 09:31:55",
            "last_seen_utc": "2026-08-10 10:56:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871609": [
        {
            "ioc_value": "stimmt.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:30:36",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871607": [
        {
            "ioc_value": "147.124.212.143:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 09:26:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "proxylife"
        }
    ],
    "1871606": [
        {
            "ioc_value": "igxpbym.enus-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:24:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871605": [
        {
            "ioc_value": "meow.schoolprojectxyz.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-10 09:21:57",
            "last_seen_utc": "2026-08-10 09:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/809ea6ebd9a87909a033616519d3c7d596b25136662da8a496ad971dbde62cf2/",
            "tags": "Mirai",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871604": [
        {
            "ioc_value": "en-en-synaptign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:21:50",
            "last_seen_utc": "2026-08-10 09:21:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "10August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871603": [
        {
            "ioc_value": "dqfqjllc.elcornerderaulmorote.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:11:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871602": [
        {
            "ioc_value": "index.ridgefield.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.revstealer",
            "malware_alias": null,
            "malware_printable": "RevStealer",
            "first_seen_utc": "2026-08-10 09:05:25",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "revstealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1871601": [
        {
            "ioc_value": "enskbzl.enus-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:03:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871600": [
        {
            "ioc_value": "enus-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 09:02:14",
            "last_seen_utc": "2026-08-10 09:33:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871599": [
        {
            "ioc_value": "sqq7n7q0.eng-en-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 08:55:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871598": [
        {
            "ioc_value": "http://luwmera.shop:5200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 08:50:07",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "remus",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1871597": [
        {
            "ioc_value": "xpeidl.spirosnet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 08:50:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871596": [
        {
            "ioc_value": "rypqfjc.greenestreetchurch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 08:43:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871592": [
        {
            "ioc_value": "drive-photopage.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.tonrat",
            "malware_alias": "TONResolver",
            "malware_printable": "TonRAT",
            "first_seen_utc": "2026-08-10 08:28:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871593": [
        {
            "ioc_value": "folder-photohotel.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.tonrat",
            "malware_alias": "TONResolver",
            "malware_printable": "TonRAT",
            "first_seen_utc": "2026-08-10 08:28:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871594": [
        {
            "ioc_value": "guestsafeimage.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.tonrat",
            "malware_alias": "TONResolver",
            "malware_printable": "TonRAT",
            "first_seen_utc": "2026-08-10 08:28:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871595": [
        {
            "ioc_value": "load-drivefile.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.tonrat",
            "malware_alias": "TONResolver",
            "malware_printable": "TonRAT",
            "first_seen_utc": "2026-08-10 08:28:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871591": [
        {
            "ioc_value": "154.29.72.36:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 08:22:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2a167fbe58a9d874dda8798e9b0d773d9316a217256a7e3f1d0c5e3e26f9f03a/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871588": [
        {
            "ioc_value": "204.77.130.227:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 08:21:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/da9442ac1174544216a00fb1792f7ee019cb708e47cd5948a9632e24285b36cb/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871589": [
        {
            "ioc_value": "204.77.130.227:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 08:21:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/da9442ac1174544216a00fb1792f7ee019cb708e47cd5948a9632e24285b36cb/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871590": [
        {
            "ioc_value": "204.77.130.227:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 08:21:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/da9442ac1174544216a00fb1792f7ee019cb708e47cd5948a9632e24285b36cb/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871580": [
        {
            "ioc_value": "89.167.18.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871581": [
        {
            "ioc_value": "62.238.20.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871582": [
        {
            "ioc_value": "46.62.173.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871583": [
        {
            "ioc_value": "2.28.53.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871584": [
        {
            "ioc_value": "46.62.167.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871585": [
        {
            "ioc_value": "178.104.167.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871586": [
        {
            "ioc_value": "2.28.63.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871587": [
        {
            "ioc_value": "78.47.230.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871579": [
        {
            "ioc_value": "89.167.23.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:21:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871577": [
        {
            "ioc_value": "mittenmint.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-10 08:20:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "OffLoader",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871575": [
        {
            "ioc_value": "spc.sinism188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871576": [
        {
            "ioc_value": "tis.sinism188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871559": [
        {
            "ioc_value": "sep.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871560": [
        {
            "ioc_value": "rha.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871561": [
        {
            "ioc_value": "gve.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871562": [
        {
            "ioc_value": "ttf.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871563": [
        {
            "ioc_value": "rne.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871564": [
        {
            "ioc_value": "ndd.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871565": [
        {
            "ioc_value": "sep.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871566": [
        {
            "ioc_value": "rha.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871567": [
        {
            "ioc_value": "gve.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871568": [
        {
            "ioc_value": "ttf.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871569": [
        {
            "ioc_value": "blh.slotmacau188e.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871570": [
        {
            "ioc_value": "dfd.slotmacau188e.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871571": [
        {
            "ioc_value": "ran.slotmacau188e.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871572": [
        {
            "ioc_value": "ign.slotmacau188e.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871573": [
        {
            "ioc_value": "xox.slotmacau188bd.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871574": [
        {
            "ioc_value": "xox.sinism188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871556": [
        {
            "ioc_value": "pas.bikhoki.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871557": [
        {
            "ioc_value": "rne.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871558": [
        {
            "ioc_value": "ndd.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871550": [
        {
            "ioc_value": "https://46.62.173.126/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871551": [
        {
            "ioc_value": "https://2.28.53.243/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871552": [
        {
            "ioc_value": "https://46.62.167.86/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871553": [
        {
            "ioc_value": "https://178.104.167.253/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871554": [
        {
            "ioc_value": "https://2.28.63.136/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871555": [
        {
            "ioc_value": "https://78.47.230.34/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871546": [
        {
            "ioc_value": "https://spc.sinism188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871547": [
        {
            "ioc_value": "https://tis.sinism188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871548": [
        {
            "ioc_value": "https://89.167.18.40/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:13",
            "last_seen_utc": "2026-08-11 03:25:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871549": [
        {
            "ioc_value": "https://62.238.20.117/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871540": [
        {
            "ioc_value": "https://dfd.slotmacau188e.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871541": [
        {
            "ioc_value": "https://ran.slotmacau188e.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871542": [
        {
            "ioc_value": "https://www.slotmacau188e.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871543": [
        {
            "ioc_value": "https://ign.slotmacau188e.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871544": [
        {
            "ioc_value": "https://xox.slotmacau188bd.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871545": [
        {
            "ioc_value": "https://xox.sinism188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871534": [
        {
            "ioc_value": "https://ndd.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871535": [
        {
            "ioc_value": "https://sep.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871536": [
        {
            "ioc_value": "https://rha.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871537": [
        {
            "ioc_value": "https://gve.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871538": [
        {
            "ioc_value": "https://ttf.sm188auto.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871539": [
        {
            "ioc_value": "https://blh.slotmacau188e.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871530": [
        {
            "ioc_value": "https://sep.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871531": [
        {
            "ioc_value": "https://rha.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871532": [
        {
            "ioc_value": "https://gve.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871533": [
        {
            "ioc_value": "https://ttf.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871526": [
        {
            "ioc_value": "https://steamcommunity.com/profiles/76561198660175584",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871527": [
        {
            "ioc_value": "https://telegram.me/j0tt0s",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871528": [
        {
            "ioc_value": "https://rne.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871529": [
        {
            "ioc_value": "https://ndd.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:19:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871525": [
        {
            "ioc_value": "task.pantryly83.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.revstealer",
            "malware_alias": null,
            "malware_printable": "RevStealer",
            "first_seen_utc": "2026-08-10 08:18:32",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "revstealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1871523": [
        {
            "ioc_value": "uybwveyvyt62rc.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-08-10 08:18:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871524": [
        {
            "ioc_value": "zsv2c62243.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-08-10 08:18:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871521": [
        {
            "ioc_value": "https://xop.beras1.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:15:05",
            "last_seen_utc": "2026-08-11 03:30:14",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871522": [
        {
            "ioc_value": "xop.sm188auto.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:15:05",
            "last_seen_utc": "2026-08-10 10:25:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871520": [
        {
            "ioc_value": "xop.beras1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 08:15:04",
            "last_seen_utc": "2026-08-10 10:26:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1871519": [
        {
            "ioc_value": "7ve71wpr.eng-neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 08:14:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871518": [
        {
            "ioc_value": "119.45.239.141:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 08:08:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871517": [
        {
            "ioc_value": "49.235.110.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 08:08:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871516": [
        {
            "ioc_value": "149.28.37.137:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-10 08:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871515": [
        {
            "ioc_value": "hhhazm.shop-gutdrops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 07:59:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871514": [
        {
            "ioc_value": "64.89.160.16:3322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:58:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6eba72e816768b1c383487af637ddc3d64e5feacaed1bd7312b983bf28478ecd/",
            "tags": "LxBaseRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871513": [
        {
            "ioc_value": "customers.googlesecuritysystem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:58:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6eba72e816768b1c383487af637ddc3d64e5feacaed1bd7312b983bf28478ecd/",
            "tags": "LxBaseRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871512": [
        {
            "ioc_value": "kjwhklm.greenestreetchurch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 07:55:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871511": [
        {
            "ioc_value": "142.132.253.231:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-08-10 07:51:25",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f6a89afd80bcfccc8ade155c0ef92a770de44610efdcac2b6a21650dc136dca5/",
            "tags": "PureLogsStealer",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871510": [
        {
            "ioc_value": "yuming.zx-infinity.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.coinminer",
            "malware_alias": null,
            "malware_printable": "Coinminer",
            "first_seen_utc": "2026-08-10 07:45:30",
            "last_seen_utc": "2026-08-10 07:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b32181caa8383569167918025e985ed2e629cf2f0f001dcfd576044c8f31599f/",
            "tags": "CoinMiner,dropped-by-gcleaner",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871509": [
        {
            "ioc_value": "tax-preparer-security-viewer.federal-portal.es",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:41:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/52dd8b2f9145907477a6ebc4ad406c1e4b221ea967f1c2ce8bc23faa83b663d8/",
            "tags": "BreezeRMM",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871507": [
        {
            "ioc_value": "52.203.242.163:7835",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:38:15",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f50e1120cc6cb993c6f6ba8c734df7855df0cd37cf634d407abffbb9f0660702/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871508": [
        {
            "ioc_value": "52.203.242.163:7890",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:38:15",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/f50e1120cc6cb993c6f6ba8c734df7855df0cd37cf634d407abffbb9f0660702/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871489": [
        {
            "ioc_value": "https://versionpi81.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871490": [
        {
            "ioc_value": "https://riderls32.life/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871491": [
        {
            "ioc_value": "https://rogethat231.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871492": [
        {
            "ioc_value": "fashion-chicken.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871493": [
        {
            "ioc_value": "https://id-verif-code.info/api.php",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871494": [
        {
            "ioc_value": "158.94.211.92:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871495": [
        {
            "ioc_value": "https://dolpi812.life/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871496": [
        {
            "ioc_value": "https://accrenpi813.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871497": [
        {
            "ioc_value": "https://thankingpi.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871499": [
        {
            "ioc_value": "https://bunntyca.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871498": [
        {
            "ioc_value": "https://wikkkipi12.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871500": [
        {
            "ioc_value": "https://tokerjoker.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871501": [
        {
            "ioc_value": "https://atomento10.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871502": [
        {
            "ioc_value": "https://frontalback91.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871503": [
        {
            "ioc_value": "https://corrykro.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871504": [
        {
            "ioc_value": "https://rumbaju42.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871505": [
        {
            "ioc_value": "https://nick-metry.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:23",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871506": [
        {
            "ioc_value": "https://borrowskol312.icu/t.js",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:33:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871483": [
        {
            "ioc_value": "https://babacan.lol/mods/api/log-download",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:22:02",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,Stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871471": [
        {
            "ioc_value": "babacan.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_stealer",
            "malware_alias": null,
            "malware_printable": "Unknown Stealer",
            "first_seen_utc": "2026-08-10 07:22:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,stealer",
            "anonymous": 0,
            "reporter": "Whanos"
        }
    ],
    "1871472": [
        {
            "ioc_value": "http://72.255.19.251:56706/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 07:22:00",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/72.255.19.251",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871484": [
        {
            "ioc_value": "https://babacan.lol/ws",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:21:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,Stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871485": [
        {
            "ioc_value": "https://babacan.lol/?p=",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:21:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,Stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871486": [
        {
            "ioc_value": "https://babacan.lol/get/config",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:21:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,Stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871487": [
        {
            "ioc_value": "https://babacan.lol/babayla/zor/yarisirlar/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-10 07:21:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "IRAHook,RAT,Stealer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871488": [
        {
            "ioc_value": "http://cc602316.tw1.ru/L1nc0In.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 07:20:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871482": [
        {
            "ioc_value": "64.89.161.78:2817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-08-10 07:15:31",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/71bbe25652524477008004b568cb32d3ed5c07693c763fc7ae673060a2e04d1a/",
            "tags": "remcos",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871481": [
        {
            "ioc_value": "4i3lqas7.en-us-en-prostawive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 07:09:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871480": [
        {
            "ioc_value": "lahtbx.shop-digestistart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 07:09:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871477": [
        {
            "ioc_value": "106.75.178.185:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-10 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871478": [
        {
            "ioc_value": "155.117.224.68:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-10 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871479": [
        {
            "ioc_value": "noiojjl.greaternewzionbc.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871475": [
        {
            "ioc_value": "102.117.174.217:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 07:05:05",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871476": [
        {
            "ioc_value": "20.215.224.217:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-10 07:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871474": [
        {
            "ioc_value": "files.orchestratorlabs.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.acr_stealer",
            "malware_alias": null,
            "malware_printable": "ACR Stealer",
            "first_seen_utc": "2026-08-10 06:38:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871473": [
        {
            "ioc_value": "117.24.4.112:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 06:28:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871320": [
        {
            "ioc_value": "161.35.48.40:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-10 06:18:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871331": [
        {
            "ioc_value": "veralok.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:18:08",
            "last_seen_utc": "2026-08-10 09:11:41",
            "confidence_level": 75,
            "is_compromised": true,
            "reference": "https://www.clickfixed.uk/intel/7165",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "ClickFixer"
        }
    ],
    "1871351": [
        {
            "ioc_value": "mail.cope.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-10 06:18:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871352": [
        {
            "ioc_value": "smtp.cope.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-10 06:18:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871357": [
        {
            "ioc_value": "46.151.182.200:60195",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-10 06:18:05",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "mirai",
            "anonymous": 0,
            "reporter": "seckle"
        }
    ],
    "1871376": [
        {
            "ioc_value": "testmyopinion.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-10 06:18:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://x.com/Malwarehunterr/status/2086517188085871074",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1871377": [
        {
            "ioc_value": "ownnewstoday.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-08-10 06:18:04",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://x.com/Malwarehunterr/status/2086517188085871074",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1871399": [
        {
            "ioc_value": "91.219.238.82:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-10 06:18:03",
            "last_seen_utc": null,
            "confidence_level": 99,
            "is_compromised": false,
            "reference": "https://www.joesandbox.com/analysis/1911456",
            "tags": null,
            "anonymous": 0,
            "reporter": "netresec"
        }
    ],
    "1871400": [
        {
            "ioc_value": "91.219.238.166:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.purelogs",
            "malware_alias": null,
            "malware_printable": "PureLogs Stealer",
            "first_seen_utc": "2026-08-10 06:18:03",
            "last_seen_utc": "2026-08-09 20:17:25",
            "confidence_level": 99,
            "is_compromised": false,
            "reference": "https://www.joesandbox.com/analysis/1911456",
            "tags": null,
            "anonymous": 0,
            "reporter": "netresec"
        }
    ],
    "1871401": [
        {
            "ioc_value": "91.219.238.82:8541",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xworm",
            "malware_alias": null,
            "malware_printable": "XWorm",
            "first_seen_utc": "2026-08-10 06:18:02",
            "last_seen_utc": null,
            "confidence_level": 99,
            "is_compromised": false,
            "reference": "https://www.joesandbox.com/analysis/1911456",
            "tags": null,
            "anonymous": 0,
            "reporter": "netresec"
        }
    ],
    "1871402": [
        {
            "ioc_value": "91.219.238.166:8045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 06:18:01",
            "last_seen_utc": null,
            "confidence_level": 66,
            "is_compromised": false,
            "reference": "https://www.joesandbox.com/analysis/1911456",
            "tags": null,
            "anonymous": 0,
            "reporter": "netresec"
        }
    ],
    "1871412": [
        {
            "ioc_value": "180.93.116.41:56999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-10 06:18:01",
            "last_seen_utc": null,
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": "mirai",
            "anonymous": 0,
            "reporter": "seckle"
        }
    ],
    "1871422": [
        {
            "ioc_value": "http://178.16.54.109/bolodo",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "win.phorpiex",
            "malware_alias": "Tldr,Trik,TwizT,phorphiex",
            "malware_printable": "Phorpiex",
            "first_seen_utc": "2026-08-10 06:18:00",
            "last_seen_utc": "2026-08-10 13:27:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Download,Phorpiex",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871419": [
        {
            "ioc_value": "https://89.167.23.148",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 06:17:59",
            "last_seen_utc": "2026-08-11 03:27:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "4abfe3aee56aad747a75a5aba1eefaa3,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871423": [
        {
            "ioc_value": "riderls32.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:17:58",
            "last_seen_utc": "2026-08-10 07:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,injected-loader",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871424": [
        {
            "ioc_value": "dolpi812.life",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:17:57",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,injected-loader",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871425": [
        {
            "ioc_value": "japansnowaccommodation.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:17:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised,EXT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871428": [
        {
            "ioc_value": "https://fashion-chicken.com/x9i32md/w1/la02",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:17:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "exfil,Magecart,skimmer",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871435": [
        {
            "ioc_value": "http://175.107.36.125:37662/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-10 06:17:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/175.107.36.125",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871429": [
        {
            "ioc_value": "https://pas.bikhoki.cc",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 06:17:54",
            "last_seen_utc": "2026-08-11 03:27:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a25ee28cbbb467ba56cb86c45a2edf9e,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871470": [
        {
            "ioc_value": "mzpdgxi.graphicstabletreviews.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 06:17:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871438": [
        {
            "ioc_value": "https://vokhmiwmncjba.vivaldinotabot.com/s/psc4?cl",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-10 06:17:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "0xKyle"
        }
    ],
    "1871440": [
        {
            "ioc_value": "130.94.14.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 06:17:53",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "2914,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1871439": [
        {
            "ioc_value": "206.237.12.167:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-10 06:17:52",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "932,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1871441": [
        {
            "ioc_value": "34.11.43.142:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-10 06:17:51",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "396982,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1871445": [
        {
            "ioc_value": "130.12.180.51:43782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.redtail",
            "malware_alias": null,
            "malware_printable": "RedTail",
            "first_seen_utc": "2026-08-10 06:17:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,redtail",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871446": [
        {
            "ioc_value": "blackjacktrailerjacks.com.au",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:17:50",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "carrier,compromised,EtherHiding",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871455": [
        {
            "ioc_value": "137.184.70.190:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-10 06:17:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871459": [
        {
            "ioc_value": "https://rne.sm188auto.top",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 06:17:48",
            "last_seen_utc": "2026-08-11 03:26:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a25ee28cbbb467ba56cb86c45a2edf9e,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871463": [
        {
            "ioc_value": "https://xop.sm188auto.top",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-10 06:17:48",
            "last_seen_utc": "2026-08-10 10:25:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "a25ee28cbbb467ba56cb86c45a2edf9e,c2,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871468": [
        {
            "ioc_value": "expressbatteryreplacement.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 06:17:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871469": [
        {
            "ioc_value": "pdlgsg.shop-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 06:17:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871467": [
        {
            "ioc_value": "kfbhnux.grannygshemporium.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 05:27:29",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871466": [
        {
            "ioc_value": "ehhzba.rsfoodproducts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 05:26:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871465": [
        {
            "ioc_value": "lh3i8c4x.en-energyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 05:08:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871464": [
        {
            "ioc_value": "qtu3bnjl.eng-en-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 04:44:25",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871462": [
        {
            "ioc_value": "masvingocity.org.zw",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 04:36:13",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871461": [
        {
            "ioc_value": "hcbjmx.nurvearmor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 04:35:03",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871460": [
        {
            "ioc_value": "zwaorbx.fungame777.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 04:33:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871458": [
        {
            "ioc_value": "apartments-vrfy5123.sbs",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 04:06:12",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,compromised",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871457": [
        {
            "ioc_value": "tdflhz.josephmichaelnh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 03:46:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871456": [
        {
            "ioc_value": "qspkxyl.finkfamilyautomotive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 03:37:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871454": [
        {
            "ioc_value": "vfq871xi.eng-eng-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 03:14:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871453": [
        {
            "ioc_value": "meogaidw.en-en-eng-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 03:05:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871451": [
        {
            "ioc_value": "143.92.52.207:2078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-10 03:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871452": [
        {
            "ioc_value": "169.58.150.130:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-10 03:05:06",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871450": [
        {
            "ioc_value": "qmxskr.healthfoodzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 02:54:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871449": [
        {
            "ioc_value": "lseeetm.federationofpbos.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 02:47:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871448": [
        {
            "ioc_value": "sxvgrh.havenchurchraleigh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 02:08:13",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871447": [
        {
            "ioc_value": "zgeetmr.enus-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 01:56:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871444": [
        {
            "ioc_value": "hqwgki.habbofutbol.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 01:13:27",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871443": [
        {
            "ioc_value": "4lmn5pp8.eachway-multiplier.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 01:07:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871442": [
        {
            "ioc_value": "nojalsd.eng--cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 01:07:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871437": [
        {
            "ioc_value": "5gghr1ol.eng-echoxen.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 00:34:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871436": [
        {
            "ioc_value": "zwqbnl.gtacauto.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 00:26:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871434": [
        {
            "ioc_value": "aqfcvod.en-usa-sugarmute.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 00:15:47",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871433": [
        {
            "ioc_value": "http://tokjoza.shop:5200/files",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 00:05:49",
            "last_seen_utc": "2026-08-10 01:09:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/43b7219764a030a1b3f8466421890f8433928152aee42a497d0d2e4ed1284a98/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871432": [
        {
            "ioc_value": "http://shkpiva.shop:5627/attachments",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 00:05:48",
            "last_seen_utc": "2026-08-10 01:09:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/43b7219764a030a1b3f8466421890f8433928152aee42a497d0d2e4ed1284a98/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871431": [
        {
            "ioc_value": "http://beljaro.shop:2536/payments",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-10 00:05:46",
            "last_seen_utc": "2026-08-10 01:09:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/43b7219764a030a1b3f8466421890f8433928152aee42a497d0d2e4ed1284a98/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871430": [
        {
            "ioc_value": "xqsxioa.en-usa-sugarmute.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-10 00:04:39",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871427": [
        {
            "ioc_value": "ykmmud.en-us-en-gold-align.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 23:33:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871426": [
        {
            "ioc_value": "en-us-en-gold-align.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 23:31:15",
            "last_seen_utc": "2026-08-09 23:31:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871421": [
        {
            "ioc_value": "wbdstjk.en-usa-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 23:12:42",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871420": [
        {
            "ioc_value": "hujg7soj.drubenginecologo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 23:04:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871418": [
        {
            "ioc_value": "khivoeg.en-usa-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 22:49:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871417": [
        {
            "ioc_value": "kbagif.en-us-energyrevolutionsystem.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 22:43:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871416": [
        {
            "ioc_value": "en-us-energyrevolutionsystem.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 22:40:49",
            "last_seen_utc": "2026-08-09 22:42:07",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "9August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871415": [
        {
            "ioc_value": "a0xhb08v.eng--slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 22:14:35",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871414": [
        {
            "ioc_value": "qcijapw.en-usa-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 21:58:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871413": [
        {
            "ioc_value": "pfnwcz.en-us-energyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 21:50:48",
            "last_seen_utc": "2026-08-11 01:25:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871411": [
        {
            "ioc_value": "vwychan.en-us-en-usa-audizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 21:08:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871410": [
        {
            "ioc_value": "xlmr6eq6.crownconnectpk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 21:04:33",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871409": [
        {
            "ioc_value": "pfbaej.enus-en-audizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 21:01:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871408": [
        {
            "ioc_value": "enus-en-audizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 20:59:43",
            "last_seen_utc": "2026-08-09 21:00:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871407": [
        {
            "ioc_value": "http://tokjoza.shop:5200/settings",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 20:50:49",
            "last_seen_utc": "2026-08-09 22:10:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3f52c9d217c625a8e8b12be29c828d27dbec62bf021d5f0d481dcced080043e8/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871406": [
        {
            "ioc_value": "http://shkpiva.shop:5627/notifications",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 20:50:46",
            "last_seen_utc": "2026-08-09 22:10:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3f52c9d217c625a8e8b12be29c828d27dbec62bf021d5f0d481dcced080043e8/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871405": [
        {
            "ioc_value": "http://beljaro.shop:2536/folders",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 20:50:42",
            "last_seen_utc": "2026-08-09 22:10:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3f52c9d217c625a8e8b12be29c828d27dbec62bf021d5f0d481dcced080043e8/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871404": [
        {
            "ioc_value": "3igbupne.eng-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 20:23:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871403": [
        {
            "ioc_value": "mgeehor.prostavve.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 20:21:41",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871398": [
        {
            "ioc_value": "fhodxy.en-us-echoxen.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 20:14:14",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871397": [
        {
            "ioc_value": "geraldmetroz.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 20:11:11",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871396": [
        {
            "ioc_value": "en-us-echoxen.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 20:09:33",
            "last_seen_utc": "2026-08-09 20:10:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871395": [
        {
            "ioc_value": "91.202.233.151:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 19:46:19",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871394": [
        {
            "ioc_value": "91.202.233.151:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 19:46:18",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871393": [
        {
            "ioc_value": "85.209.87.84:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:46:13",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871392": [
        {
            "ioc_value": "49.235.153.53:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-09 19:45:52",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871390": [
        {
            "ioc_value": "45.140.204.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-09 19:45:38",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871391": [
        {
            "ioc_value": "45.140.204.12:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-09 19:45:38",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871389": [
        {
            "ioc_value": "217.60.77.60:4782",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:45:16",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871388": [
        {
            "ioc_value": "2.50.170.49:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 19:44:29",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871387": [
        {
            "ioc_value": "128.90.59.58:1110",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871386": [
        {
            "ioc_value": "107.172.133.190:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 19:43:12",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871385": [
        {
            "ioc_value": "104.164.46.182:52203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 19:43:08",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871384": [
        {
            "ioc_value": "rgutfmf.prosta--vive.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 19:28:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871383": [
        {
            "ioc_value": "bebnmr.enus-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 19:21:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871382": [
        {
            "ioc_value": "otarires.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 19:21:10",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871381": [
        {
            "ioc_value": "enus-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 19:18:45",
            "last_seen_utc": "2026-08-09 19:19:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871380": [
        {
            "ioc_value": "d9ycd24u.pro--prostavive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 19:05:49",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871378": [
        {
            "ioc_value": "111.229.135.130:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871379": [
        {
            "ioc_value": "139.196.181.1:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 19:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871375": [
        {
            "ioc_value": "hasebtb.en-us--gold-align.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 18:36:16",
            "last_seen_utc": "2026-08-09 18:36:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871374": [
        {
            "ioc_value": "en-usgold-align.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 18:35:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871373": [
        {
            "ioc_value": "ezhlrk.en-usechoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 18:30:16",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871372": [
        {
            "ioc_value": "en-usechoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 18:28:12",
            "last_seen_utc": "2026-08-09 18:28:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871371": [
        {
            "ioc_value": "http://tokjoza.shop:5200/orders",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 18:01:03",
            "last_seen_utc": "2026-08-09 19:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/cfa7e41d09f3d4fa04300b72f0f71f6b8af79369de528eeaf03a813ee1636ee5/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871370": [
        {
            "ioc_value": "http://onesdto.shop:2535/collections",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 18:00:58",
            "last_seen_utc": "2026-08-09 19:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/cfa7e41d09f3d4fa04300b72f0f71f6b8af79369de528eeaf03a813ee1636ee5/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871369": [
        {
            "ioc_value": "http://beljaro.shop:2536/tags",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 18:00:54",
            "last_seen_utc": "2026-08-09 19:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/cfa7e41d09f3d4fa04300b72f0f71f6b8af79369de528eeaf03a813ee1636ee5/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871368": [
        {
            "ioc_value": "uaawnpt.en-us-en-us-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 17:47:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871367": [
        {
            "ioc_value": "en-us-en-us-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 17:45:03",
            "last_seen_utc": "2026-08-09 17:46:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871366": [
        {
            "ioc_value": "tfgrzf.enus-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 17:38:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871365": [
        {
            "ioc_value": "enus-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 17:37:42",
            "last_seen_utc": "2026-08-10 01:55:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871364": [
        {
            "ioc_value": "h0snck00.elcornerderaulmorote.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 17:13:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871363": [
        {
            "ioc_value": "64.90.11.101:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 17:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871362": [
        {
            "ioc_value": "od8872b0.nurvearmor.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 17:03:21",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871361": [
        {
            "ioc_value": "kiavqge.en-us-en-usa-audizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 16:59:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871360": [
        {
            "ioc_value": "en-us-en-usa-audizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 16:54:31",
            "last_seen_utc": "2026-08-09 21:07:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871359": [
        {
            "ioc_value": "qkyear.en-usa-sugarmute.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 16:39:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871358": [
        {
            "ioc_value": "uv8fudow.eng--keyslimdrops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 16:14:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871356": [
        {
            "ioc_value": "64.90.11.101:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 16:05:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871355": [
        {
            "ioc_value": "uamidyb.en-us-en-prostawive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 15:58:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871353": [
        {
            "ioc_value": "en-us-en-prostawive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 15:54:00",
            "last_seen_utc": "2026-08-10 07:08:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871350": [
        {
            "ioc_value": "khypcp.en-usa-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 15:36:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871348": [
        {
            "ioc_value": "64.90.11.101:3306",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871349": [
        {
            "ioc_value": "64.90.11.101:9321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 15:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871347": [
        {
            "ioc_value": "64.90.11.101:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 15:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871346": [
        {
            "ioc_value": "5j5spglj.engus-prostavive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 15:03:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871345": [
        {
            "ioc_value": "wxfruqi.shop-digestistart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 14:57:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871344": [
        {
            "ioc_value": "prozenith-en-us.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 14:41:20",
            "last_seen_utc": "2026-08-09 14:41:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871343": [
        {
            "ioc_value": "bhnyau.en-usa-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 14:35:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871342": [
        {
            "ioc_value": "prozeanith.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 14:31:26",
            "last_seen_utc": "2026-08-09 14:32:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871341": [
        {
            "ioc_value": "prozeanith.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 14:27:51",
            "last_seen_utc": "2026-08-09 14:28:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871339": [
        {
            "ioc_value": "8.218.211.108:3232",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871340": [
        {
            "ioc_value": "64.90.11.101:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 14:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871338": [
        {
            "ioc_value": "31.7.62.178:12583",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 14:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871337": [
        {
            "ioc_value": "72.61.112.206:2536",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 14:01:05",
            "last_seen_utc": "2026-08-10 19:35:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1a51a0bda4c9e0659b94221fe0001d55038ceb742767df9b49e6e610b8592ebe/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871336": [
        {
            "ioc_value": "http://beljaro.shop:2536",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 14:01:04",
            "last_seen_utc": "2026-08-09 15:18:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1a51a0bda4c9e0659b94221fe0001d55038ceb742767df9b49e6e610b8592ebe/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871335": [
        {
            "ioc_value": "walsercup.ch",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:41:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871334": [
        {
            "ioc_value": "hkzkwr.shop-gutdrops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:36:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871333": [
        {
            "ioc_value": "shop-gutdrops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:34:29",
            "last_seen_utc": "2026-08-10 07:58:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871332": [
        {
            "ioc_value": "alzbomz.prostavve.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:32:22",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871330": [
        {
            "ioc_value": "prostavve.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:27:18",
            "last_seen_utc": "2026-08-09 20:17:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871328": [
        {
            "ioc_value": "36.140.162.173:12443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-09 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871329": [
        {
            "ioc_value": "124.222.104.163:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 13:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871327": [
        {
            "ioc_value": "169.58.82.229:3389",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-09 13:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871325": [
        {
            "ioc_value": "139.196.111.118:111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-09 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871326": [
        {
            "ioc_value": "139.196.111.118:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-09 13:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871324": [
        {
            "ioc_value": "punjabcosmetologyclinics.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:01:08",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871323": [
        {
            "ioc_value": "ccisa.org.za",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 13:01:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871322": [
        {
            "ioc_value": "maceqk.shop-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:36:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871321": [
        {
            "ioc_value": "shop-goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:33:59",
            "last_seen_utc": "2026-08-09 12:35:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871319": [
        {
            "ioc_value": "wupmugp.prosta--vive.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:27:38",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871318": [
        {
            "ioc_value": "prostavive.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:27:26",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871317": [
        {
            "ioc_value": "prosta--vive.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:27:12",
            "last_seen_utc": "2026-08-10 10:32:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "9August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871316": [
        {
            "ioc_value": "africaprosperitynetwork.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:21:07",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871234": [
        {
            "ioc_value": "159.203.172.232:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-09 12:20:57",
            "last_seen_utc": "2026-08-10 06:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871235": [
        {
            "ioc_value": "http://64.89.160.97:2404/login",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-09 12:20:57",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://x.com/solostalking/status/2086356374930468925",
            "tags": null,
            "anonymous": 0,
            "reporter": "solostalking"
        }
    ],
    "1871236": [
        {
            "ioc_value": "http://2.26.227.212:2404/login",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown_rat",
            "malware_alias": null,
            "malware_printable": "Unknown RAT",
            "first_seen_utc": "2026-08-09 12:20:56",
            "last_seen_utc": null,
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://x.com/solostalking/status/2086356374930468925",
            "tags": null,
            "anonymous": 0,
            "reporter": "solostalking"
        }
    ],
    "1871250": [
        {
            "ioc_value": "38.207.178.195:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-09 12:20:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871288": [
        {
            "ioc_value": "167.172.188.177:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-09 12:20:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871294": [
        {
            "ioc_value": "veralok.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:20:55",
            "last_seen_utc": "2026-08-09 10:17:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "ClearFake,ClickFix,EtherHiding",
            "anonymous": 0,
            "reporter": "penislandrocket"
        }
    ],
    "1871312": [
        {
            "ioc_value": "http://223.123.35.145:36473/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 12:20:55",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/223.123.35.145",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871313": [
        {
            "ioc_value": "http://99.105.56.184:51774/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 12:20:54",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/99.105.56.184",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871314": [
        {
            "ioc_value": "http://175.107.233.143:40008/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 12:20:53",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/175.107.233.143",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871315": [
        {
            "ioc_value": "http://190.196.253.37:10261/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 12:20:52",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/190.196.253.37",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871311": [
        {
            "ioc_value": "fh32dvqs.eachway-multiplier.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:13:24",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871310": [
        {
            "ioc_value": "nljtg5vk.eng--cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:03:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871309": [
        {
            "ioc_value": "alifbd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 12:02:06",
            "last_seen_utc": "2026-08-09 12:02:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "9August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871308": [
        {
            "ioc_value": "idlmwh.shop-echoxen.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:34:18",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871307": [
        {
            "ioc_value": "shop-echoxen.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:33:28",
            "last_seen_utc": "2026-08-09 11:34:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871306": [
        {
            "ioc_value": "jklqnwn.pro--prostavive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:27:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871305": [
        {
            "ioc_value": "pro--prostavive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:26:47",
            "last_seen_utc": "2026-08-09 19:02:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "9August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1871304": [
        {
            "ioc_value": "proprostavive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:26:10",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871303": [
        {
            "ioc_value": "p6b6yovt.rsfoodproducts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:25:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871302": [
        {
            "ioc_value": "kirvnj.shop-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:23:28",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871301": [
        {
            "ioc_value": "vtptolt.pink-salt.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:23:17",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871300": [
        {
            "ioc_value": "rvpsviz.pink-salt.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:14:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871299": [
        {
            "ioc_value": "pink-salt.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:11:48",
            "last_seen_utc": "2026-08-09 11:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871298": [
        {
            "ioc_value": "hhypswg.pinksalt-prozenith.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:09:51",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871297": [
        {
            "ioc_value": "pinksalt-prozenith.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 11:04:58",
            "last_seen_utc": "2026-08-09 11:05:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871296": [
        {
            "ioc_value": "utgadz.shop-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 10:47:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871295": [
        {
            "ioc_value": "shop-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 10:46:16",
            "last_seen_utc": "2026-08-09 11:22:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871293": [
        {
            "ioc_value": "dzbptpb.nurvearmor.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 10:06:37",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871292": [
        {
            "ioc_value": "nurvearmor.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 10:04:07",
            "last_seen_utc": "2026-08-09 17:02:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871291": [
        {
            "ioc_value": "eovrhf.shop-digestistart.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:57:45",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871290": [
        {
            "ioc_value": "shop-digestistart.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:56:25",
            "last_seen_utc": "2026-08-09 09:56:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871289": [
        {
            "ioc_value": "zfnv2q4q.dayvillelaundry.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:49:31",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871285": [
        {
            "ioc_value": "72.14.136.55:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:46:40",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871286": [
        {
            "ioc_value": "72.14.136.55:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:46:40",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871287": [
        {
            "ioc_value": "72.14.136.55:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:46:40",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871284": [
        {
            "ioc_value": "69.164.245.180:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-09 09:46:39",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871282": [
        {
            "ioc_value": "43.134.169.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:46:06",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871283": [
        {
            "ioc_value": "43.134.169.103:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:46:06",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871281": [
        {
            "ioc_value": "212.103.26.10:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-09 09:44:59",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871280": [
        {
            "ioc_value": "209.99.190.23:55010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:57",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871279": [
        {
            "ioc_value": "20.243.82.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 09:44:49",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871278": [
        {
            "ioc_value": "198.37.105.30:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 09:44:43",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871277": [
        {
            "ioc_value": "185.247.208.91:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:28",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871275": [
        {
            "ioc_value": "172.252.172.33:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:10",
            "last_seen_utc": "2026-08-11 02:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871276": [
        {
            "ioc_value": "172.252.172.33:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:10",
            "last_seen_utc": "2026-08-11 02:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871272": [
        {
            "ioc_value": "172.252.172.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871273": [
        {
            "ioc_value": "172.252.172.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871274": [
        {
            "ioc_value": "172.252.172.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871269": [
        {
            "ioc_value": "172.245.136.99:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:08",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871270": [
        {
            "ioc_value": "172.245.136.99:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:08",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871271": [
        {
            "ioc_value": "172.245.136.99:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:08",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871268": [
        {
            "ioc_value": "168.222.251.83:56012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:44:04",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871264": [
        {
            "ioc_value": "138.2.87.233:25745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871265": [
        {
            "ioc_value": "138.2.87.233:30462",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871266": [
        {
            "ioc_value": "138.2.87.233:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871267": [
        {
            "ioc_value": "139.162.113.221:64321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:33",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871263": [
        {
            "ioc_value": "134.122.132.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:29",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871262": [
        {
            "ioc_value": "130.12.182.39:2700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871261": [
        {
            "ioc_value": "124.221.215.82:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-09 09:43:24",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871260": [
        {
            "ioc_value": "105.108.109.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-09 09:43:14",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871259": [
        {
            "ioc_value": "ftayov.shop-digestistart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:30:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871258": [
        {
            "ioc_value": "shop-digestistart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:27:36",
            "last_seen_utc": "2026-08-10 07:08:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871257": [
        {
            "ioc_value": "pv0onuvi.habbofutbol.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:25:46",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871256": [
        {
            "ioc_value": "60guam39.drubenginecologo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:23:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871255": [
        {
            "ioc_value": "xkycfjc.nurvearmor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:05:56",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871254": [
        {
            "ioc_value": "nurvearmor.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 09:04:08",
            "last_seen_utc": "2026-08-10 04:34:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871253": [
        {
            "ioc_value": "35416ynp.thecharcuteriebeach.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:55:30",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871252": [
        {
            "ioc_value": "snuidm.shop-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:28:40",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871251": [
        {
            "ioc_value": "shop-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:27:04",
            "last_seen_utc": "2026-08-10 06:16:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871249": [
        {
            "ioc_value": "syztfq.proznith.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:12:53",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871248": [
        {
            "ioc_value": "proznith.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:11:23",
            "last_seen_utc": "2026-08-09 08:12:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871247": [
        {
            "ioc_value": "prozeniths.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:10:11",
            "last_seen_utc": "2026-08-09 08:10:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871246": [
        {
            "ioc_value": "coowyhw.nuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:09:01",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871245": [
        {
            "ioc_value": "p85gkugy.gtacauto.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:07:12",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871244": [
        {
            "ioc_value": "5.83.150.71:4567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2026-08-09 08:05:09",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "quasarrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871242": [
        {
            "ioc_value": "20.3.144.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 08:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871243": [
        {
            "ioc_value": "45.61.136.78:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 08:05:08",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871241": [
        {
            "ioc_value": "216.128.131.6:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 08:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871240": [
        {
            "ioc_value": "207.189.23.189:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-09 08:05:05",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871239": [
        {
            "ioc_value": "nuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 08:03:39",
            "last_seen_utc": "2026-08-09 08:04:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871238": [
        {
            "ioc_value": "dmrhew.prozenith-pinksalt.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:57:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871237": [
        {
            "ioc_value": "prozenith-pinksalt.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:54:57",
            "last_seen_utc": "2026-08-09 07:56:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871233": [
        {
            "ioc_value": "waiwqo.alifpaints.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:13:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871232": [
        {
            "ioc_value": "alifpaints.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:11:47",
            "last_seen_utc": "2026-08-09 07:12:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871231": [
        {
            "ioc_value": "rhdqfzs.en-try-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:08:32",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871228": [
        {
            "ioc_value": "117.72.41.61:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871229": [
        {
            "ioc_value": "120.26.14.56:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871230": [
        {
            "ioc_value": "198.46.216.194:8084",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 07:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871227": [
        {
            "ioc_value": "alifbuy.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:03:34",
            "last_seen_utc": "2026-08-09 07:04:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871226": [
        {
            "ioc_value": "en-try-echoxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 07:03:07",
            "last_seen_utc": "2026-08-09 07:04:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871225": [
        {
            "ioc_value": "vmi3469820.contaboserver.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:59:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/c7b2edcd0f5c24dd5e571a1983c5c514e7d2e6ef2e0268a3f43d50d79076e69e/",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871150": [
        {
            "ioc_value": "159.203.172.232:37215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-09 06:31:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871154": [
        {
            "ioc_value": "191.252.159.33:8539",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-09 06:31:00",
            "last_seen_utc": "2026-08-09 07:23:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,d2a9afc03e8d4d0f85017c9598f91db6,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1871166": [
        {
            "ioc_value": "mail.coping.ink",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-09 06:30:59",
            "last_seen_utc": "2026-08-09 07:39:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871167": [
        {
            "ioc_value": "79.143.191.7:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-09 06:30:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871169": [
        {
            "ioc_value": "ui-portal.mekebibsolomonlaw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2026-08-09 06:30:59",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/117062649106026987",
            "tags": "SocGholish",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1871170": [
        {
            "ioc_value": "http://153.117.9.227:35316/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/153.117.9.227",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871171": [
        {
            "ioc_value": "http://202.141.104.249:60065/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:58",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/202.141.104.249",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871172": [
        {
            "ioc_value": "http://223.123.126.147:40242/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/223.123.126.147",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871173": [
        {
            "ioc_value": "http://101.53.225.7:52865/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:57",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/101.53.225.7",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871174": [
        {
            "ioc_value": "fashion-chicken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown_loader",
            "malware_alias": null,
            "malware_printable": "Unknown Loader",
            "first_seen_utc": "2026-08-09 06:30:56",
            "last_seen_utc": "2026-08-09 23:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "c2,gate",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1871180": [
        {
            "ioc_value": "smtp.coping.ink",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-09 06:30:56",
            "last_seen_utc": "2026-08-09 07:39:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871184": [
        {
            "ioc_value": "94.154.43.87:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-09 06:30:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "C2,Mirai",
            "anonymous": 0,
            "reporter": "botnetkiller"
        }
    ],
    "1871186": [
        {
            "ioc_value": "stoppingignpi.buzz",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:30:55",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,injected-loader",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871187": [
        {
            "ioc_value": "rogethat231.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:30:54",
            "last_seen_utc": "2026-08-10 07:21:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,injected-loader",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871188": [
        {
            "ioc_value": "tokerjoker.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:30:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,injected-loader",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871220": [
        {
            "ioc_value": "http://223.123.124.0:54646/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:50",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/223.123.124.0",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871221": [
        {
            "ioc_value": "http://115.55.183.61:57147/Mozi.a",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:48",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/115.55.183.61",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871222": [
        {
            "ioc_value": "http://182.116.13.153:48985/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/182.116.13.153",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871223": [
        {
            "ioc_value": "http://61.71.179.32:58000/Mozi.m",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "elf.mozi",
            "malware_alias": null,
            "malware_printable": "Mozi",
            "first_seen_utc": "2026-08-09 06:30:47",
            "last_seen_utc": null,
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://honeylabs.net/lookup/61.71.179.32",
            "tags": "elf,iot,Mozi",
            "anonymous": 0,
            "reporter": "HoneyLabs"
        }
    ],
    "1871224": [
        {
            "ioc_value": "chevron-shipping.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 06:26:04",
            "last_seen_utc": "2026-08-09 06:36:04",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871219": [
        {
            "ioc_value": "zodem5ma.fungame777.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 06:05:54",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871218": [
        {
            "ioc_value": "202.60.232.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:05:06",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871217": [
        {
            "ioc_value": "34.26.129.189:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 06:05:05",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871216": [
        {
            "ioc_value": "icovaj.sivasumutemlak.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 06:04:44",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871215": [
        {
            "ioc_value": "ubmjfvn.en-thyrafemme-balance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 06:03:04",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871214": [
        {
            "ioc_value": "en-thyrafemme-balance.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 06:03:00",
            "last_seen_utc": "2026-08-09 06:03:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871213": [
        {
            "ioc_value": "eqppqrur.crownconnectpk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 05:38:52",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0xfb64,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871212": [
        {
            "ioc_value": "183.60.226.2:110",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-09 05:05:05",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "supershell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871211": [
        {
            "ioc_value": "ueplmeq.vivmart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 05:04:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871209": [
        {
            "ioc_value": "fihwfp.hallmarkcarpets.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 05:03:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871208": [
        {
            "ioc_value": "vivmart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 05:02:08",
            "last_seen_utc": "2026-08-09 05:03:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1871207": [
        {
            "ioc_value": "physiotherapie-am-kreuz.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 04:21:04",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871206": [
        {
            "ioc_value": "dm6oaevq.spirosnet.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 04:05:58",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871205": [
        {
            "ioc_value": "182.92.188.8:500",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 04:05:08",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871204": [
        {
            "ioc_value": "155.117.224.68:21",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 04:05:07",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871203": [
        {
            "ioc_value": "111.228.27.89:4567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2026-08-09 04:05:06",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vshell",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871202": [
        {
            "ioc_value": "bmebamc.eng-usa--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 04:03:36",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871201": [
        {
            "ioc_value": "nmcjvm.gregoryschreiercabinetmaker.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 04:02:34",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871200": [
        {
            "ioc_value": "7streamsacquisitions.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 04:01:02",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871199": [
        {
            "ioc_value": "msbusinesscentre.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 04:01:01",
            "last_seen_utc": null,
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "compromised,EtherHide",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871198": [
        {
            "ioc_value": "xzzxhqm.eng-us--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 03:55:19",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871197": [
        {
            "ioc_value": "dtcjz3h1.takeoffdallas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 03:55:11",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871196": [
        {
            "ioc_value": "jhjokx.sweethannahs.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 03:54:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871195": [
        {
            "ioc_value": "jlwaxyd.eng-us--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 03:54:00",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871194": [
        {
            "ioc_value": "ivxxyaq.eng-us--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 03:48:43",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871193": [
        {
            "ioc_value": "hhmqcnz.greenestreetchurch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-09 03:40:48",
            "last_seen_utc": null,
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871165": [
        {
            "ioc_value": "68.64.183.64:9088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-08 23:47:03",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871153": [
        {
            "ioc_value": "jyhdzq.eng-us--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 21:19:06",
            "last_seen_utc": "2026-08-11 01:37:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871134": [
        {
            "ioc_value": "91.92.40.5:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-08 19:46:26",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871133": [
        {
            "ioc_value": "57.182.128.31:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-08 19:46:05",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871131": [
        {
            "ioc_value": "52.128.231.157:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:03",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871132": [
        {
            "ioc_value": "52.128.231.158:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:03",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871129": [
        {
            "ioc_value": "52.128.231.155:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:02",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871130": [
        {
            "ioc_value": "52.128.231.156:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:46:02",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871128": [
        {
            "ioc_value": "43.139.114.212:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:45:40",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871127": [
        {
            "ioc_value": "34.150.91.139:19443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871126": [
        {
            "ioc_value": "207.189.18.213:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:44:39",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871125": [
        {
            "ioc_value": "194.69.162.217:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:44:25",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871123": [
        {
            "ioc_value": "191.111.244.175:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-08 19:44:19",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871122": [
        {
            "ioc_value": "172.252.172.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:58",
            "last_seen_utc": "2026-08-11 02:44:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871121": [
        {
            "ioc_value": "169.58.64.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 19:43:55",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871120": [
        {
            "ioc_value": "159.203.69.210:48202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-08 19:43:49",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871119": [
        {
            "ioc_value": "157.10.52.2:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871118": [
        {
            "ioc_value": "151.242.170.219:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:37",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871116": [
        {
            "ioc_value": "125.62.77.141:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871117": [
        {
            "ioc_value": "125.62.77.141:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871112": [
        {
            "ioc_value": "112.121.176.3:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871113": [
        {
            "ioc_value": "112.121.176.4:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871114": [
        {
            "ioc_value": "112.121.176.5:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871115": [
        {
            "ioc_value": "112.121.176.6:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871111": [
        {
            "ioc_value": "104.239.66.95:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 19:43:11",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871110": [
        {
            "ioc_value": "1.92.135.168:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 19:43:01",
            "last_seen_utc": "2026-08-11 02:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1871094": [
        {
            "ioc_value": "38.60.227.165:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 18:05:08",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1871093": [
        {
            "ioc_value": "37.72.168.212:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 18:05:07",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870822": [
        {
            "ioc_value": "eng-usa-sugarmute.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 17:16:25",
            "last_seen_utc": "2026-08-10 23:16:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870807": [
        {
            "ioc_value": "bpiaasi.en-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 16:45:34",
            "last_seen_utc": "2026-08-10 21:25:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870782": [
        {
            "ioc_value": "eng-usa-sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 14:14:42",
            "last_seen_utc": "2026-08-09 23:12:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870772": [
        {
            "ioc_value": "engus-prostavive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 13:41:21",
            "last_seen_utc": "2026-08-09 15:02:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870756": [
        {
            "ioc_value": "192.255.236.156:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-08 12:05:06",
            "last_seen_utc": "2026-08-10 06:28:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870752": [
        {
            "ioc_value": "185.92.190.177:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-08 11:47:11",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870750": [
        {
            "ioc_value": "eng-usa--goldalign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 11:40:32",
            "last_seen_utc": "2026-08-09 04:02:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "8August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1870715": [
        {
            "ioc_value": "eng-usa-digestistart.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 09:52:07",
            "last_seen_utc": "2026-08-10 13:04:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870714": [
        {
            "ioc_value": "95.133.229.173:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:46:41",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870713": [
        {
            "ioc_value": "88.129.145.223:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-08 09:46:32",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870712": [
        {
            "ioc_value": "68.178.202.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:46:21",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870710": [
        {
            "ioc_value": "45.56.165.197:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:45:58",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870711": [
        {
            "ioc_value": "45.56.165.197:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:45:58",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870709": [
        {
            "ioc_value": "45.157.117.186:27487",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:45:54",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870708": [
        {
            "ioc_value": "34.81.234.183:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-08 09:45:42",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870707": [
        {
            "ioc_value": "31.77.145.53:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:45:41",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870706": [
        {
            "ioc_value": "217.60.195.187:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-08 09:45:29",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870705": [
        {
            "ioc_value": "209.99.190.23:55011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:44:45",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870704": [
        {
            "ioc_value": "203.98.68.17:1111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-08 09:44:39",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870703": [
        {
            "ioc_value": "2.59.133.115:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:44:36",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870702": [
        {
            "ioc_value": "2.26.30.62:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-08-08 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870701": [
        {
            "ioc_value": "195.242.119.86:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-08 09:44:30",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870700": [
        {
            "ioc_value": "194.59.31.175:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:44:28",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870699": [
        {
            "ioc_value": "172.252.172.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:43:59",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870698": [
        {
            "ioc_value": "136.244.96.75:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 09:43:27",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870697": [
        {
            "ioc_value": "134.122.132.35:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-08 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870696": [
        {
            "ioc_value": "129.146.57.192:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-08 09:43:22",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870694": [
        {
            "ioc_value": "eng--sightfresh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 09:42:08",
            "last_seen_utc": "2026-08-11 03:14:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "8August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1870688": [
        {
            "ioc_value": "eng-usa-bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 09:06:39",
            "last_seen_utc": "2026-08-10 12:02:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870641": [
        {
            "ioc_value": "192.169.176.54:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 07:05:05",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870636": [
        {
            "ioc_value": "njdwpg.eng--nitrilean.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 06:47:37",
            "last_seen_utc": "2026-08-10 13:14:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870481": [
        {
            "ioc_value": "https://set.turbo88galaxy.top",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-08 06:35:55",
            "last_seen_utc": "2026-08-11 00:29:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,c948db7ccfb97f2f0bfa248274085e2d,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1870600": [
        {
            "ioc_value": "versionpi81.icu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 06:35:31",
            "last_seen_utc": "2026-08-10 07:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix,injected-loader",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870614": [
        {
            "ioc_value": "139.59.144.8:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-08 06:35:28",
            "last_seen_utc": "2026-08-10 23:42:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1870634": [
        {
            "ioc_value": "vmi3474645.contaboserver.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 06:23:18",
            "last_seen_utc": "2026-08-09 06:59:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/6e679d77e2ca2f8cfbbe65306d0dea83fc3363ab2254a2afe33ac82f821fdd87/",
            "tags": "geo,MEX",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870625": [
        {
            "ioc_value": "axinjur.eng--slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 05:21:09",
            "last_seen_utc": "2026-08-10 18:15:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870622": [
        {
            "ioc_value": "eng--neuroxen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 05:16:43",
            "last_seen_utc": "2026-08-11 03:06:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "8August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1870610": [
        {
            "ioc_value": "68.178.205.17:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-08 04:05:05",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1870584": [
        {
            "ioc_value": "eng-energyrevolution.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 02:17:06",
            "last_seen_utc": "2026-08-10 05:06:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870566": [
        {
            "ioc_value": "eng-en-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 01:31:32",
            "last_seen_utc": "2026-08-10 04:43:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870563": [
        {
            "ioc_value": "eng--keyslimdrops.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 01:28:28",
            "last_seen_utc": "2026-08-09 16:12:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "8August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1870558": [
        {
            "ioc_value": "eng-echoxen.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-08 00:46:20",
            "last_seen_utc": "2026-08-10 00:33:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870522": [
        {
            "ioc_value": "eng-en-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 23:57:23",
            "last_seen_utc": "2026-08-10 08:54:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870520": [
        {
            "ioc_value": "121.5.27.17:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 23:46:45",
            "last_seen_utc": "2026-08-11 02:47:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870519": [
        {
            "ioc_value": "1302768123-l3a4w496qm.ap-shanghai.tencentscf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 23:46:29",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870509": [
        {
            "ioc_value": "eng-eng-slimsounds.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 23:11:51",
            "last_seen_utc": "2026-08-10 03:14:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870254": [
        {
            "ioc_value": "94.154.32.48:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:46:31",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870253": [
        {
            "ioc_value": "87.120.196.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-07 19:46:22",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870252": [
        {
            "ioc_value": "43.135.34.69:43911",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-07 19:45:42",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870251": [
        {
            "ioc_value": "38.18.229.217:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:45:39",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870250": [
        {
            "ioc_value": "217.60.97.106:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 19:45:24",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870249": [
        {
            "ioc_value": "207.231.104.146:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 19:44:41",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870248": [
        {
            "ioc_value": "207.189.18.213:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:44:40",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870247": [
        {
            "ioc_value": "186.169.88.130:9002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 19:44:18",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870246": [
        {
            "ioc_value": "185.212.128.59:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 19:44:13",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870244": [
        {
            "ioc_value": "172.239.45.42:82",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-07 19:43:59",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870245": [
        {
            "ioc_value": "172.86.117.104:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:43:59",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870243": [
        {
            "ioc_value": "167.172.145.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-07 19:43:55",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870242": [
        {
            "ioc_value": "159.203.69.210:11088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 19:43:49",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870241": [
        {
            "ioc_value": "124.198.131.130:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870240": [
        {
            "ioc_value": "104.238.57.23:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:43:11",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870239": [
        {
            "ioc_value": "103.158.191.249:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 19:43:06",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1870235": [
        {
            "ioc_value": "eng--bpzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 19:24:26",
            "last_seen_utc": "2026-08-09 20:23:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "7August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1870225": [
        {
            "ioc_value": "en-en-eng-cognisurge.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 18:40:35",
            "last_seen_utc": "2026-08-10 03:05:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1870209": [
        {
            "ioc_value": "byqpgf.digeststart.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 17:53:48",
            "last_seen_utc": "2026-08-10 00:23:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869963": [
        {
            "ioc_value": "ttf.slotmacau188e.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-07 15:45:04",
            "last_seen_utc": "2026-08-10 08:19:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1869958": [
        {
            "ioc_value": "https://ttf.bayototo.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-07 15:25:05",
            "last_seen_utc": "2026-08-11 03:25:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1869957": [
        {
            "ioc_value": "ttf.bayototo.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-07 15:25:04",
            "last_seen_utc": "2026-08-11 03:25:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1869884": [
        {
            "ioc_value": "167.172.188.177:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-07 14:59:47",
            "last_seen_utc": "2026-08-09 18:56:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869863": [
        {
            "ioc_value": "161.35.48.40:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-07 14:12:06",
            "last_seen_utc": "2026-08-10 15:32:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869870": [
        {
            "ioc_value": "buy-ignitra.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 14:05:23",
            "last_seen_utc": "2026-08-10 23:32:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869855": [
        {
            "ioc_value": "165.245.178.39:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-07 13:23:31",
            "last_seen_utc": "2026-08-10 18:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869794": [
        {
            "ioc_value": "43.139.87.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-07 10:05:08",
            "last_seen_utc": "2026-08-10 08:08:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869784": [
        {
            "ioc_value": "id-verif-code.info",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-07 09:56:53",
            "last_seen_utc": "2026-08-10 07:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869781": [
        {
            "ioc_value": "85.209.87.84:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:46:36",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869780": [
        {
            "ioc_value": "78.17.71.8:5025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 09:46:29",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869779": [
        {
            "ioc_value": "64.89.161.196:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-07 09:46:24",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869778": [
        {
            "ioc_value": "45.89.48.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:46:10",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869777": [
        {
            "ioc_value": "34.106.101.107:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:45:46",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869776": [
        {
            "ioc_value": "3.75.210.48:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-07 09:45:43",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869775": [
        {
            "ioc_value": "207.32.217.227:21903",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:44:48",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869774": [
        {
            "ioc_value": "203.98.68.17:1009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:44:45",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869773": [
        {
            "ioc_value": "185.212.129.152:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869772": [
        {
            "ioc_value": "185.212.128.170:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-07 09:44:18",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869771": [
        {
            "ioc_value": "159.203.69.210:35203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:43:53",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869769": [
        {
            "ioc_value": "154.30.132.30:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:43:42",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869770": [
        {
            "ioc_value": "154.40.62.125:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-08-07 09:43:42",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869768": [
        {
            "ioc_value": "124.198.131.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:43:22",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869767": [
        {
            "ioc_value": "103.249.116.184:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-07 09:43:06",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869755": [
        {
            "ioc_value": "139.59.144.8:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-07 09:39:43",
            "last_seen_utc": "2026-08-09 20:30:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869750": [
        {
            "ioc_value": "203.98.68.17:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-07 09:05:08",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869731": [
        {
            "ioc_value": "aaudizen.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 08:30:16",
            "last_seen_utc": "2026-08-09 09:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869729": [
        {
            "ioc_value": "bp-zone.us",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 08:29:37",
            "last_seen_utc": "2026-08-09 14:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869601": [
        {
            "ioc_value": "valley-open-mri.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-07 00:08:57",
            "last_seen_utc": "2026-08-09 08:56:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869592": [
        {
            "ioc_value": "151.242.125.190:9527",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 23:46:46",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869558": [
        {
            "ioc_value": "91.92.40.56:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:26",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869556": [
        {
            "ioc_value": "80.76.49.3:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:15",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869557": [
        {
            "ioc_value": "80.76.49.3:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:15",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869555": [
        {
            "ioc_value": "64.89.161.42:13834",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:46:09",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869554": [
        {
            "ioc_value": "31.59.137.166:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869553": [
        {
            "ioc_value": "217.60.97.106:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-06 19:45:21",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869552": [
        {
            "ioc_value": "185.212.128.232:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-06 19:44:11",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869551": [
        {
            "ioc_value": "156.251.16.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869550": [
        {
            "ioc_value": "154.37.154.36:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:38",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869549": [
        {
            "ioc_value": "153.75.88.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 19:43:37",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869524": [
        {
            "ioc_value": "196.251.121.185:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-06 19:28:07",
            "last_seen_utc": "2026-08-10 12:48:16",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "apex,botnet,payload-delivery",
            "anonymous": 0,
            "reporter": "nullblue67"
        }
    ],
    "1869525": [
        {
            "ioc_value": "5.182.210.174:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-06 19:28:06",
            "last_seen_utc": "2026-08-10 12:48:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,honeypot",
            "anonymous": 0,
            "reporter": "nullblue67"
        }
    ],
    "1869517": [
        {
            "ioc_value": "triumphplumbinginc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-06 18:04:50",
            "last_seen_utc": "2026-08-09 03:56:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869498": [
        {
            "ioc_value": "https://web.bayototo.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-06 15:35:05",
            "last_seen_utc": "2026-08-10 12:20:08",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1869453": [
        {
            "ioc_value": "103.213.248.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 14:05:06",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869429": [
        {
            "ioc_value": "takeoffdallas.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-06 13:30:28",
            "last_seen_utc": "2026-08-09 03:54:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869414": [
        {
            "ioc_value": "143.198.206.191:9035",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 13:15:37",
            "last_seen_utc": "2026-08-10 04:48:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869410": [
        {
            "ioc_value": "tadkaindiaka.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-06 12:45:00",
            "last_seen_utc": "2026-08-09 14:42:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869404": [
        {
            "ioc_value": "dayvillelaundry.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-06 12:32:36",
            "last_seen_utc": "2026-08-09 09:47:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "6August2026,ClearFake,Commandline,DomainShadowing,Windows",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1869385": [
        {
            "ioc_value": "https://ign.bayototo.org/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-06 11:55:05",
            "last_seen_utc": "2026-08-10 11:14:44",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1869383": [
        {
            "ioc_value": "8.135.68.39:2087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:32",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869382": [
        {
            "ioc_value": "185.92.190.176:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:16",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869381": [
        {
            "ioc_value": "185.92.190.173:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:15",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869380": [
        {
            "ioc_value": "139.199.3.92:2087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-06 11:47:09",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869378": [
        {
            "ioc_value": "sweethannahs.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-06 11:44:53",
            "last_seen_utc": "2026-08-09 03:53:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869339": [
        {
            "ioc_value": "94.154.32.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:46:43",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869338": [
        {
            "ioc_value": "88.214.26.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:46:35",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869337": [
        {
            "ioc_value": "80.225.83.93:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-08-06 09:46:27",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869336": [
        {
            "ioc_value": "57.154.16.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:46:15",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869335": [
        {
            "ioc_value": "31.77.145.53:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:45:42",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869334": [
        {
            "ioc_value": "209.99.190.23:56013",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:44:47",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869333": [
        {
            "ioc_value": "207.174.0.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:44:43",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869332": [
        {
            "ioc_value": "206.123.129.171:7720",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-06 09:44:42",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869331": [
        {
            "ioc_value": "20.168.52.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:44:38",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869330": [
        {
            "ioc_value": "20.150.148.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-06 09:44:37",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869329": [
        {
            "ioc_value": "196.64.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-06 09:44:32",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869327": [
        {
            "ioc_value": "186.112.66.56:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-08-06 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869328": [
        {
            "ioc_value": "186.169.88.130:9031",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-06 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869326": [
        {
            "ioc_value": "172.239.45.42:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-06 09:43:59",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869324": [
        {
            "ioc_value": "159.203.69.210:22555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-06 09:43:50",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869325": [
        {
            "ioc_value": "159.203.69.210:5800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-06 09:43:50",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869323": [
        {
            "ioc_value": "134.122.132.28:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-06 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869304": [
        {
            "ioc_value": "thecharcuteriebeach.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-06 08:36:37",
            "last_seen_utc": "2026-08-09 08:55:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1869273": [
        {
            "ioc_value": "188.166.222.192:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 07:02:53",
            "last_seen_utc": "2026-08-09 17:19:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869082": [
        {
            "ioc_value": "38.207.178.195:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:22",
            "last_seen_utc": "2026-08-11 03:20:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869122": [
        {
            "ioc_value": "167.172.188.177:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:20",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869123": [
        {
            "ioc_value": "159.65.136.5:7647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-06 05:10:19",
            "last_seen_utc": "2026-08-10 17:56:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "0f81469cc7638ba7c82eaddbd6b3c20a,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869124": [
        {
            "ioc_value": "159.203.172.232:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:18",
            "last_seen_utc": "2026-08-11 03:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869125": [
        {
            "ioc_value": "188.166.222.192:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:18",
            "last_seen_utc": "2026-08-11 03:23:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869126": [
        {
            "ioc_value": "161.35.48.40:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:16",
            "last_seen_utc": "2026-08-11 03:23:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869127": [
        {
            "ioc_value": "165.245.178.39:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:15",
            "last_seen_utc": "2026-08-11 03:23:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869128": [
        {
            "ioc_value": "139.59.144.8:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:15",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869133": [
        {
            "ioc_value": "38.207.178.195:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-06 05:10:14",
            "last_seen_utc": "2026-08-11 02:25:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1869105": [
        {
            "ioc_value": "217.154.212.25:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 23:47:16",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869104": [
        {
            "ioc_value": "100.82.195.65:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 23:46:54",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869103": [
        {
            "ioc_value": "hp.tailc223d4.ts.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 23:46:49",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869057": [
        {
            "ioc_value": "94.250.176.76:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-05 19:47:11",
            "last_seen_utc": "2026-08-11 02:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869055": [
        {
            "ioc_value": "85.209.87.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:46:59",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869056": [
        {
            "ioc_value": "86.48.16.94:30200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:46:59",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869054": [
        {
            "ioc_value": "72.14.136.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:46:50",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869052": [
        {
            "ioc_value": "64.95.13.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:46:47",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869053": [
        {
            "ioc_value": "64.95.13.164:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:46:47",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869051": [
        {
            "ioc_value": "45.59.120.82:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-05 19:46:26",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869050": [
        {
            "ioc_value": "206.123.129.171:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:59",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869047": [
        {
            "ioc_value": "196.251.107.131:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:48",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869048": [
        {
            "ioc_value": "196.64.146.72:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:48",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869049": [
        {
            "ioc_value": "196.64.146.72:5001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:48",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869046": [
        {
            "ioc_value": "185.212.129.31:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:31",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869044": [
        {
            "ioc_value": "185.212.129.170:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869045": [
        {
            "ioc_value": "185.212.129.25:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869043": [
        {
            "ioc_value": "185.212.128.181:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:29",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869042": [
        {
            "ioc_value": "185.212.128.124:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 19:44:28",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869041": [
        {
            "ioc_value": "185.174.103.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:44:27",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869040": [
        {
            "ioc_value": "178.16.53.222:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:44:19",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869039": [
        {
            "ioc_value": "172.81.132.75:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:44:13",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869038": [
        {
            "ioc_value": "159.203.69.210:23501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 19:44:00",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869037": [
        {
            "ioc_value": "154.247.251.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 19:43:48",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869036": [
        {
            "ioc_value": "130.12.181.96:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-05 19:43:28",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1869030": [
        {
            "ioc_value": "158.220.100.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:05:06",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869029": [
        {
            "ioc_value": "134.209.146.147:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 19:05:05",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1869026": [
        {
            "ioc_value": "https://spc.y8slot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-05 18:40:05",
            "last_seen_utc": "2026-08-11 03:30:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1869000": [
        {
            "ioc_value": "8.156.69.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 17:05:05",
            "last_seen_utc": "2026-08-11 02:47:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868874": [
        {
            "ioc_value": "142.132.211.95:4938",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-05 13:27:18",
            "last_seen_utc": "2026-08-09 03:40:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "18464deb5c573a0c110ed3fc702af680,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868828": [
        {
            "ioc_value": "47.83.3.103:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:40",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868827": [
        {
            "ioc_value": "45.8.159.205:8596",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:36",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868826": [
        {
            "ioc_value": "209.200.246.194:16556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:30",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868825": [
        {
            "ioc_value": "169.58.82.229:7788",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:47:25",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868823": [
        {
            "ioc_value": "acac.hopto.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 11:46:59",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868784": [
        {
            "ioc_value": "143.198.206.191:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-05 11:43:46",
            "last_seen_utc": "2026-08-09 06:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868789": [
        {
            "ioc_value": "161.35.153.254:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:45",
            "last_seen_utc": "2026-08-10 09:27:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868790": [
        {
            "ioc_value": "104.248.195.124:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:44",
            "last_seen_utc": "2026-08-10 09:24:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868791": [
        {
            "ioc_value": "104.248.196.94:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:44",
            "last_seen_utc": "2026-08-10 09:30:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868792": [
        {
            "ioc_value": "159.223.214.253:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:42",
            "last_seen_utc": "2026-08-10 09:23:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868793": [
        {
            "ioc_value": "64.227.73.206:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:42",
            "last_seen_utc": "2026-08-10 09:27:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868794": [
        {
            "ioc_value": "64.227.67.30:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:41",
            "last_seen_utc": "2026-08-10 09:24:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868795": [
        {
            "ioc_value": "152.42.134.198:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:41",
            "last_seen_utc": "2026-08-10 09:27:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868796": [
        {
            "ioc_value": "161.35.159.53:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:41",
            "last_seen_utc": "2026-08-10 09:28:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868797": [
        {
            "ioc_value": "159.223.220.225:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 11:43:40",
            "last_seen_utc": "2026-08-10 09:28:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868776": [
        {
            "ioc_value": "104.248.199.73:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-08-05 10:19:02",
            "last_seen_utc": "2026-08-10 09:26:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868757": [
        {
            "ioc_value": "65.1.70.222:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:46:52",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868756": [
        {
            "ioc_value": "64.227.159.29:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:51",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868755": [
        {
            "ioc_value": "64.20.61.215:5000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:46:50",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868754": [
        {
            "ioc_value": "57.154.16.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:46",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868753": [
        {
            "ioc_value": "45.38.20.38:8491",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:46:29",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868752": [
        {
            "ioc_value": "43.135.26.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:46:19",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868751": [
        {
            "ioc_value": "36.248.232.165:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:46:13",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868750": [
        {
            "ioc_value": "217.60.97.106:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:45:56",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868748": [
        {
            "ioc_value": "203.98.68.17:1008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:55",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868749": [
        {
            "ioc_value": "203.98.68.29:30300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:55",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868747": [
        {
            "ioc_value": "196.251.107.131:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:47",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868746": [
        {
            "ioc_value": "194.87.239.245:7682",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:44",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868745": [
        {
            "ioc_value": "193.149.185.215:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:40",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868744": [
        {
            "ioc_value": "186.244.227.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:34",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868740": [
        {
            "ioc_value": "186.169.88.130:5012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868741": [
        {
            "ioc_value": "186.169.88.130:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868742": [
        {
            "ioc_value": "186.244.227.104:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868743": [
        {
            "ioc_value": "186.244.227.27:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868736": [
        {
            "ioc_value": "185.212.129.70:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868737": [
        {
            "ioc_value": "185.212.129.89:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868738": [
        {
            "ioc_value": "185.212.131.112:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868739": [
        {
            "ioc_value": "185.212.131.113:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-05 09:44:29",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868735": [
        {
            "ioc_value": "185.174.102.28:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:44:26",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868734": [
        {
            "ioc_value": "172.81.132.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-05 09:44:12",
            "last_seen_utc": "2026-08-11 02:44:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868733": [
        {
            "ioc_value": "164.132.199.212:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-05 09:44:06",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868732": [
        {
            "ioc_value": "160.20.109.52:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-05 09:44:00",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868731": [
        {
            "ioc_value": "149.28.163.119:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-05 09:43:43",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868730": [
        {
            "ioc_value": "128.90.59.58:7070",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-05 09:43:27",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868729": [
        {
            "ioc_value": "122.51.212.92:39901",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-05 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868683": [
        {
            "ioc_value": "169.58.82.229:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 08:05:05",
            "last_seen_utc": "2026-08-10 08:08:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868671": [
        {
            "ioc_value": "207.57.134.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 07:36:43",
            "last_seen_utc": "2026-08-10 08:08:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868506": [
        {
            "ioc_value": "137.184.70.190:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-05 06:37:56",
            "last_seen_utc": "2026-08-09 22:12:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868636": [
        {
            "ioc_value": "43.108.51.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-05 06:05:05",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868569": [
        {
            "ioc_value": "210.56.48.227:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 23:47:37",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868570": [
        {
            "ioc_value": "222.255.215.42:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 23:47:37",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868535": [
        {
            "ioc_value": "https://psk.y8slot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-04 21:45:06",
            "last_seen_utc": "2026-08-11 03:27:52",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1868533": [
        {
            "ioc_value": "https://psk.sinism188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-04 21:45:05",
            "last_seen_utc": "2026-08-11 02:25:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1868532": [
        {
            "ioc_value": "psk.sinism188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-04 21:45:04",
            "last_seen_utc": "2026-08-11 02:25:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1868505": [
        {
            "ioc_value": "93.82.26.41:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-08-04 19:46:40",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868504": [
        {
            "ioc_value": "80.96.109.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:46:26",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868503": [
        {
            "ioc_value": "43.134.169.103:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-04 19:45:49",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868502": [
        {
            "ioc_value": "35.202.238.13:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-04 19:45:43",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868501": [
        {
            "ioc_value": "31.76.96.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-08-04 19:45:42",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868500": [
        {
            "ioc_value": "3.122.223.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 19:45:38",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868499": [
        {
            "ioc_value": "207.189.25.132:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:44",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868498": [
        {
            "ioc_value": "203.98.68.17:30200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 19:44:42",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868497": [
        {
            "ioc_value": "195.177.94.71:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:33",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868495": [
        {
            "ioc_value": "176.97.114.8:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:09",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868496": [
        {
            "ioc_value": "176.97.114.8:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:44:09",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868494": [
        {
            "ioc_value": "172.182.216.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 19:44:03",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868492": [
        {
            "ioc_value": "161.97.154.193:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:55",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868493": [
        {
            "ioc_value": "161.97.154.193:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:55",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868491": [
        {
            "ioc_value": "153.75.88.67:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868490": [
        {
            "ioc_value": "105.108.17.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 19:43:15",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868489": [
        {
            "ioc_value": "100.31.3.235:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-08-04 19:43:02",
            "last_seen_utc": "2026-08-11 02:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868453": [
        {
            "ioc_value": "61.54.27.211:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "vbs.vbrevshell",
            "malware_alias": null,
            "malware_printable": "VBREVSHELL",
            "first_seen_utc": "2026-08-04 18:00:04",
            "last_seen_utc": "2026-08-11 03:24:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=61.54.27.211",
            "tags": "ViriBack,Vshell",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868335": [
        {
            "ioc_value": "https://com.y8slot.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-04 14:40:06",
            "last_seen_utc": "2026-08-11 03:30:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1868334": [
        {
            "ioc_value": "https://com.sinism188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-04 14:40:05",
            "last_seen_utc": "2026-08-10 12:30:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1868328": [
        {
            "ioc_value": "130.12.182.39:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 14:05:07",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868327": [
        {
            "ioc_value": "130.12.182.39:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 14:05:06",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868319": [
        {
            "ioc_value": "130.12.182.39:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 13:05:09",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868287": [
        {
            "ioc_value": "79.110.49.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 11:47:25",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868286": [
        {
            "ioc_value": "169.58.82.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 11:47:08",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868285": [
        {
            "ioc_value": "102.204.223.230:5554",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 11:46:52",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868277": [
        {
            "ioc_value": "onesourceautollc.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-04 11:15:58",
            "last_seen_utc": "2026-08-09 09:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake",
            "anonymous": 0,
            "reporter": "threatcat_ch"
        }
    ],
    "1868255": [
        {
            "ioc_value": "91.92.42.152:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 09:46:41",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868254": [
        {
            "ioc_value": "89.36.231.206:65432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:46:38",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868253": [
        {
            "ioc_value": "81.177.222.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 09:46:30",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868252": [
        {
            "ioc_value": "45.61.176.146:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-04 09:46:05",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868251": [
        {
            "ioc_value": "45.139.226.224:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:45:57",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868250": [
        {
            "ioc_value": "27.124.36.136:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:45:40",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868247": [
        {
            "ioc_value": "178.16.53.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868248": [
        {
            "ioc_value": "178.16.53.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868246": [
        {
            "ioc_value": "172.111.232.133:7775",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-04 09:44:00",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868244": [
        {
            "ioc_value": "172.111.134.94:56011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:59",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868245": [
        {
            "ioc_value": "172.111.134.94:56012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:59",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868241": [
        {
            "ioc_value": "140.228.29.61:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:31",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868240": [
        {
            "ioc_value": "138.124.62.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-04 09:43:30",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868239": [
        {
            "ioc_value": "130.12.182.39:5333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868238": [
        {
            "ioc_value": "122.51.212.92:39905",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-08-04 09:43:23",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868237": [
        {
            "ioc_value": "104.251.181.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:14",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868236": [
        {
            "ioc_value": "104.239.66.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-04 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868235": [
        {
            "ioc_value": "104.223.98.68:2028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-04 09:43:11",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868193": [
        {
            "ioc_value": "178.16.55.104:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 08:50:29",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/e7303de39d7b302ea161b61c4200b40ec9303dd848893096dced28351e2f4370/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868177": [
        {
            "ioc_value": "206.238.42.153:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-04 08:18:19",
            "last_seen_utc": "2026-08-10 08:08:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1868107": [
        {
            "ioc_value": "136.115.85.178:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 06:05:07",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1868106": [
        {
            "ioc_value": "195.177.94.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-04 06:05:06",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867971": [
        {
            "ioc_value": "189.249.195.86:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 05:21:19",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://platform.censys.io/hosts/189.249.195.86?at_time=2026-08-03T16%3A58%3A19.500825484Z",
            "tags": "AS 8151,c2,censys,mythic,online",
            "anonymous": 0,
            "reporter": "f1nd3r"
        }
    ],
    "1868044": [
        {
            "ioc_value": "109.104.155.94:5326",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-04 05:21:08",
            "last_seen_utc": "2026-08-10 20:41:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "440d77642bde0cd5bdd42e3b046983f2,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1868042": [
        {
            "ioc_value": "157.230.83.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-04 02:05:06",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867932": [
        {
            "ioc_value": "https://nonobody123.com/a85e9a98b9364c5d8f74.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-08-03 19:54:25",
            "last_seen_utc": "2026-08-11 03:09:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,loader,NEWN1,StealC,stealer",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867961": [
        {
            "ioc_value": "5.56.25.151:6680",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-03 19:45:50",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867960": [
        {
            "ioc_value": "45.61.176.146:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-03 19:45:41",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867959": [
        {
            "ioc_value": "45.59.120.79:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-03 19:45:40",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867958": [
        {
            "ioc_value": "23.160.168.51:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:45:16",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867957": [
        {
            "ioc_value": "217.60.195.197:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:45:13",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867956": [
        {
            "ioc_value": "198.46.173.17:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-03 19:44:25",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867955": [
        {
            "ioc_value": "161.97.154.193:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 19:43:49",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867954": [
        {
            "ioc_value": "130.12.182.39:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-03 19:43:23",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867807": [
        {
            "ioc_value": "185.194.218.82:4930",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-03 12:43:11",
            "last_seen_utc": "2026-08-10 04:41:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,e1c021a2a661457101d90095eb3b4696,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867786": [
        {
            "ioc_value": "91.206.178.155:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-08-03 09:46:43",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867785": [
        {
            "ioc_value": "80.76.49.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:46:33",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867784": [
        {
            "ioc_value": "45.61.176.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-03 09:46:06",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867783": [
        {
            "ioc_value": "207.56.28.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:44:45",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867782": [
        {
            "ioc_value": "207.56.28.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:44:44",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867781": [
        {
            "ioc_value": "193.112.169.214:30727",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-03 09:44:27",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867780": [
        {
            "ioc_value": "192.159.99.55:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-03 09:44:24",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867779": [
        {
            "ioc_value": "135.136.132.74:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-03 09:43:28",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867777": [
        {
            "ioc_value": "104.207.90.3:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-03 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867778": [
        {
            "ioc_value": "104.207.90.93:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-03 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867752": [
        {
            "ioc_value": "178.105.99.239:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:05:14",
            "last_seen_utc": "2026-08-10 08:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867725": [
        {
            "ioc_value": "vog.peluangsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 09:04:36",
            "last_seen_utc": "2026-08-11 03:25:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867710": [
        {
            "ioc_value": "https://2.28.15.55/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:30",
            "last_seen_utc": "2026-08-11 03:29:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867714": [
        {
            "ioc_value": "https://62.238.55.102/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:30",
            "last_seen_utc": "2026-08-11 03:28:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867700": [
        {
            "ioc_value": "https://37.27.193.182/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:28",
            "last_seen_utc": "2026-08-11 03:29:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867702": [
        {
            "ioc_value": "https://37.27.197.184/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:28",
            "last_seen_utc": "2026-08-11 03:27:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867693": [
        {
            "ioc_value": "https://178.105.99.239/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:26",
            "last_seen_utc": "2026-08-11 03:25:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867668": [
        {
            "ioc_value": "https://vog.peluangsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-08-03 08:50:20",
            "last_seen_utc": "2026-08-11 03:25:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1867634": [
        {
            "ioc_value": "137.184.199.120:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-03 08:40:47",
            "last_seen_utc": "2026-08-09 20:43:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867640": [
        {
            "ioc_value": "92.119.158.20:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-03 07:05:06",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867546": [
        {
            "ioc_value": "198.98.53.100:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-03 05:45:46",
            "last_seen_utc": "2026-08-10 15:49:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867590": [
        {
            "ioc_value": "82.156.11.154:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-03 01:05:05",
            "last_seen_utc": "2026-08-11 02:47:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867535": [
        {
            "ioc_value": "38.60.230.135:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:45:45",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867536": [
        {
            "ioc_value": "38.60.230.135:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:45:45",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867537": [
        {
            "ioc_value": "38.60.230.135:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:45:45",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867534": [
        {
            "ioc_value": "27.124.36.153:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:35",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867532": [
        {
            "ioc_value": "217.60.77.60:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:28",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867533": [
        {
            "ioc_value": "217.60.77.60:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:45:28",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867530": [
        {
            "ioc_value": "207.56.28.108:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:44:42",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867531": [
        {
            "ioc_value": "207.56.28.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 19:44:42",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867529": [
        {
            "ioc_value": "198.46.173.17:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:44:33",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867528": [
        {
            "ioc_value": "176.97.114.8:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-02 19:44:07",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867527": [
        {
            "ioc_value": "109.248.151.114:9829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 19:43:18",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867317": [
        {
            "ioc_value": "mfoguyg.josephmichaelnh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-02 14:54:06",
            "last_seen_utc": "2026-08-11 03:15:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867310": [
        {
            "ioc_value": "85.31.60.169:5627",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-02 14:37:15",
            "last_seen_utc": "2026-08-10 19:35:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,ca8ec1b5a0a17aa5d1b792ebceadba97,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867274": [
        {
            "ioc_value": "106.75.249.202:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-02 11:46:58",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867257": [
        {
            "ioc_value": "43.131.251.190:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-02 10:05:06",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867254": [
        {
            "ioc_value": "91.124.98.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:59",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867253": [
        {
            "ioc_value": "45.61.114.217:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-08-02 09:46:21",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867251": [
        {
            "ioc_value": "38.247.147.37:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:08",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867252": [
        {
            "ioc_value": "38.247.147.37:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:08",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867250": [
        {
            "ioc_value": "38.247.147.37:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:46:07",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867248": [
        {
            "ioc_value": "31.57.147.182:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:45:57",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867249": [
        {
            "ioc_value": "31.57.147.182:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:45:57",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867247": [
        {
            "ioc_value": "198.46.187.30:65528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-02 09:44:44",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867246": [
        {
            "ioc_value": "194.59.30.183:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-02 09:44:39",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867245": [
        {
            "ioc_value": "178.16.55.237:6443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-02 09:44:17",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867244": [
        {
            "ioc_value": "162.35.187.214:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-02 09:44:03",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867243": [
        {
            "ioc_value": "15.235.204.51:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-02 09:43:44",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867236": [
        {
            "ioc_value": "104.168.123.242:3276",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-02 09:29:59",
            "last_seen_utc": "2026-08-11 01:17:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "945c9f3c8cddcb7f33efce50a9a949ad,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866984": [
        {
            "ioc_value": "143.198.206.191:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-02 06:55:00",
            "last_seen_utc": "2026-08-09 06:31:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1867146": [
        {
            "ioc_value": "oitavwl.dusanperisicmd.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-02 00:26:48",
            "last_seen_utc": "2026-08-10 05:24:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1867044": [
        {
            "ioc_value": "54.178.100.27:8022",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:47:05",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867043": [
        {
            "ioc_value": "185.92.190.177:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:46:49",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867042": [
        {
            "ioc_value": "156.224.18.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:46:46",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1867041": [
        {
            "ioc_value": "cs.rainbowrain.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-08-01 23:46:25",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866972": [
        {
            "ioc_value": "64.20.61.215:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 19:46:16",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866971": [
        {
            "ioc_value": "46.246.82.10:6490",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-08-01 19:46:07",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866970": [
        {
            "ioc_value": "45.192.211.77:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:45:56",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866969": [
        {
            "ioc_value": "217.60.77.60:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:45:32",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866968": [
        {
            "ioc_value": "195.177.94.61:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:44:38",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866967": [
        {
            "ioc_value": "155.2.192.251:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:46",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866966": [
        {
            "ioc_value": "139.199.160.80:32408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:31",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866963": [
        {
            "ioc_value": "104.251.181.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866964": [
        {
            "ioc_value": "106.53.107.131:30943",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866965": [
        {
            "ioc_value": "107.152.42.223:34321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866962": [
        {
            "ioc_value": "103.148.58.18:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 19:43:07",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866960": [
        {
            "ioc_value": "101.36.123.12:34321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 19:43:03",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866961": [
        {
            "ioc_value": "102.117.164.193:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 19:43:03",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866905": [
        {
            "ioc_value": "oxrdcm.gtacauto.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 16:49:50",
            "last_seen_utc": "2026-08-10 19:14:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866903": [
        {
            "ioc_value": "upnbvji.healthfoodzone.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 16:41:36",
            "last_seen_utc": "2026-08-11 01:14:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866902": [
        {
            "ioc_value": "9pulblfs.drubenginecologo.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 16:24:47",
            "last_seen_utc": "2026-08-09 23:04:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x76c7,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866900": [
        {
            "ioc_value": "ygjmeq.gregoryschreiercabinetmaker.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 16:06:32",
            "last_seen_utc": "2026-08-09 04:03:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866897": [
        {
            "ioc_value": "qdmwlwx.havenchurchraleigh.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 15:55:50",
            "last_seen_utc": "2026-08-10 23:15:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866896": [
        {
            "ioc_value": "dwdqhepzawjuizzspp.fungame777.co",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 15:44:36",
            "last_seen_utc": "2026-08-10 15:12:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0xa770,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866679": [
        {
            "ioc_value": "nfbjoi.greenestreetchurch.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 15:18:57",
            "last_seen_utc": "2026-08-10 08:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866673": [
        {
            "ioc_value": "ybfrvo.greaternewzionbc.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 14:37:38",
            "last_seen_utc": "2026-08-10 07:04:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866670": [
        {
            "ioc_value": "padpoh.graphicstabletreviews.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 13:51:45",
            "last_seen_utc": "2026-08-10 06:13:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866669": [
        {
            "ioc_value": "spobnte.hallmarkcarpets.net",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 13:39:51",
            "last_seen_utc": "2026-08-09 05:03:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866664": [
        {
            "ioc_value": "mbbzfh.grannygshemporium.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 13:06:48",
            "last_seen_utc": "2026-08-10 17:13:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866654": [
        {
            "ioc_value": "swspyli.habbofutbol.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 12:08:51",
            "last_seen_utc": "2026-08-10 21:14:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866624": [
        {
            "ioc_value": "87.199.203.248:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 09:46:41",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866622": [
        {
            "ioc_value": "85.11.167.134:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:46:39",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866623": [
        {
            "ioc_value": "85.11.167.134:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:46:39",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866621": [
        {
            "ioc_value": "77.246.111.132:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-08-01 09:46:33",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866620": [
        {
            "ioc_value": "47.87.84.177:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:46:18",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866618": [
        {
            "ioc_value": "43.213.166.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:45:59",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866619": [
        {
            "ioc_value": "43.213.254.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:45:59",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866617": [
        {
            "ioc_value": "31.57.38.232:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:50",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866616": [
        {
            "ioc_value": "3.115.55.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-01 09:45:47",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866615": [
        {
            "ioc_value": "217.60.195.197:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:39",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866614": [
        {
            "ioc_value": "217.60.195.197:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:45:38",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866613": [
        {
            "ioc_value": "202.182.108.40:21157",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:44:46",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866612": [
        {
            "ioc_value": "20.125.96.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:44:44",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866611": [
        {
            "ioc_value": "198.46.187.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-08-01 09:44:41",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866609": [
        {
            "ioc_value": "192.159.99.70:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:44:31",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866610": [
        {
            "ioc_value": "192.162.199.180:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 09:44:31",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866608": [
        {
            "ioc_value": "192.159.99.70:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:44:30",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866607": [
        {
            "ioc_value": "168.144.89.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-08-01 09:44:05",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866606": [
        {
            "ioc_value": "16.76.80.179:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-08-01 09:43:58",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866603": [
        {
            "ioc_value": "104.251.181.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:16",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866604": [
        {
            "ioc_value": "104.251.181.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:16",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866605": [
        {
            "ioc_value": "104.253.79.117:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-08-01 09:43:16",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866602": [
        {
            "ioc_value": "103.148.58.8:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:09",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866597": [
        {
            "ioc_value": "103.148.58.10:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866598": [
        {
            "ioc_value": "103.148.58.10:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866599": [
        {
            "ioc_value": "103.148.58.18:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866600": [
        {
            "ioc_value": "103.148.58.18:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866601": [
        {
            "ioc_value": "103.148.58.8:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-08-01 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866565": [
        {
            "ioc_value": "45.43.143.17:5776",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-08-01 08:50:33",
            "last_seen_utc": "2026-08-09 05:30:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,f0e7dc585ba3ebf586da7b92aedbfc64,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866367": [
        {
            "ioc_value": "137.184.70.190:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:28:01",
            "last_seen_utc": "2026-08-11 03:09:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866374": [
        {
            "ioc_value": "103.214.146.46:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:28:01",
            "last_seen_utc": "2026-08-11 02:49:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866401": [
        {
            "ioc_value": "206.189.81.41:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:28:00",
            "last_seen_utc": "2026-08-10 12:16:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866418": [
        {
            "ioc_value": "167.99.64.180:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:28:00",
            "last_seen_utc": "2026-08-10 12:34:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866467": [
        {
            "ioc_value": "167.99.64.180:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:27:58",
            "last_seen_utc": "2026-08-09 16:11:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866470": [
        {
            "ioc_value": "167.172.71.69:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-08-01 06:27:58",
            "last_seen_utc": "2026-08-10 14:19:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866471": [
        {
            "ioc_value": "jldrbcv.fitprotracker-campaign.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-08-01 01:38:22",
            "last_seen_utc": "2026-08-10 04:26:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866405": [
        {
            "ioc_value": "185.92.190.175:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:44",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866406": [
        {
            "ioc_value": "185.92.190.176:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:44",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866402": [
        {
            "ioc_value": "185.182.65.34:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:43",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866403": [
        {
            "ioc_value": "185.92.190.173:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:43",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866404": [
        {
            "ioc_value": "185.92.190.174:8696",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 23:46:43",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866400": [
        {
            "ioc_value": "gpfbmfo.finkfamilyautomotive.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-31 23:17:18",
            "last_seen_utc": "2026-08-10 13:10:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866378": [
        {
            "ioc_value": "fkgynbq.federationofpbos.org",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-31 21:00:30",
            "last_seen_utc": "2026-08-10 02:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x4679,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866354": [
        {
            "ioc_value": "167.99.64.180:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-31 19:49:36",
            "last_seen_utc": "2026-08-11 03:06:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866366": [
        {
            "ioc_value": "93.152.223.242:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-31 19:46:12",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866365": [
        {
            "ioc_value": "93.115.27.97:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:46:11",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866364": [
        {
            "ioc_value": "38.240.37.142:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:45:26",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866363": [
        {
            "ioc_value": "31.57.38.232:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:45:21",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866362": [
        {
            "ioc_value": "23.227.196.18:43655",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-31 19:45:14",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866361": [
        {
            "ioc_value": "194.62.248.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:21",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866360": [
        {
            "ioc_value": "193.138.195.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:18",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866359": [
        {
            "ioc_value": "185.174.102.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 19:44:09",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866358": [
        {
            "ioc_value": "167.172.142.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-31 19:43:52",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866357": [
        {
            "ioc_value": "118.107.46.207:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:43:20",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866355": [
        {
            "ioc_value": "118.107.46.204:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:43:19",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866356": [
        {
            "ioc_value": "118.107.46.207:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-31 19:43:19",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866335": [
        {
            "ioc_value": "206.189.81.41:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-31 19:28:12",
            "last_seen_utc": "2026-08-11 03:16:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866336": [
        {
            "ioc_value": "143.198.206.191:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-31 19:28:10",
            "last_seen_utc": "2026-08-11 03:23:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866339": [
        {
            "ioc_value": "137.184.199.120:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-31 19:28:09",
            "last_seen_utc": "2026-08-11 03:27:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866340": [
        {
            "ioc_value": "167.172.71.69:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-31 19:28:09",
            "last_seen_utc": "2026-08-11 03:13:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1866310": [
        {
            "ioc_value": "https://vog.akasia988.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-31 16:25:35",
            "last_seen_utc": "2026-08-11 03:29:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "e99set,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866062": [
        {
            "ioc_value": "156.239.47.223:6005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 11:47:13",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866061": [
        {
            "ioc_value": "156.224.18.21:8083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 11:47:12",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866034": [
        {
            "ioc_value": "188.166.238.207:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-31 10:05:08",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1866020": [
        {
            "ioc_value": "95.133.166.43:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-31 09:46:54",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866019": [
        {
            "ioc_value": "89.213.118.63:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:46:47",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866018": [
        {
            "ioc_value": "82.22.204.150:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:46:40",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866017": [
        {
            "ioc_value": "27.124.36.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:45:48",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866015": [
        {
            "ioc_value": "209.99.190.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-31 09:44:55",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866014": [
        {
            "ioc_value": "207.174.0.103:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:44:51",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866013": [
        {
            "ioc_value": "195.177.94.169:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:44:40",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866011": [
        {
            "ioc_value": "194.59.30.109:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:44:38",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866012": [
        {
            "ioc_value": "194.59.30.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:44:38",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866010": [
        {
            "ioc_value": "181.215.242.84:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866009": [
        {
            "ioc_value": "157.254.194.126:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:43:56",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866008": [
        {
            "ioc_value": "13.205.246.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-31 09:43:27",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1866007": [
        {
            "ioc_value": "104.243.248.63:3608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-31 09:43:15",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1865459": [
        {
            "ioc_value": "web.ugelparuro.gob.pe",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-31 07:14:40",
            "last_seen_utc": "2026-08-10 09:20:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1865331": [
        {
            "ioc_value": "www.gaia-us.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-31 07:13:36",
            "last_seen_utc": "2026-08-09 07:46:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1865279": [
        {
            "ioc_value": "zryjsmacznie.pl",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-31 07:12:38",
            "last_seen_utc": "2026-08-09 08:56:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1865178": [
        {
            "ioc_value": "www.pvlive.eu",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-31 07:12:32",
            "last_seen_utc": "2026-08-09 17:36:09",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "ClickFix,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1865067": [
        {
            "ioc_value": "27.71.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:43",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "7552,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1865072": [
        {
            "ioc_value": "124.220.34.180:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:41",
            "last_seen_utc": "2026-08-11 02:47:03",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1865074": [
        {
            "ioc_value": "111.170.148.141:113",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-31 05:45:40",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "151185,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1865068": [
        {
            "ioc_value": "114.132.155.197:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-31 01:05:06",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1865052": [
        {
            "ioc_value": "151.244.243.42:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-30 23:46:22",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864997": [
        {
            "ioc_value": "51.79.209.228:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:46:08",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864998": [
        {
            "ioc_value": "51.79.209.228:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:46:08",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864999": [
        {
            "ioc_value": "51.79.209.228:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:46:08",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864996": [
        {
            "ioc_value": "46.246.14.5:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:46:00",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864995": [
        {
            "ioc_value": "46.149.71.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:45:58",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864994": [
        {
            "ioc_value": "35.72.170.195:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:45:39",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864993": [
        {
            "ioc_value": "27.124.36.136:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864992": [
        {
            "ioc_value": "20.236.181.110:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:37",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864988": [
        {
            "ioc_value": "195.177.94.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864989": [
        {
            "ioc_value": "195.177.94.69:27220",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864990": [
        {
            "ioc_value": "195.177.94.69:27221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864991": [
        {
            "ioc_value": "195.242.118.106:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864986": [
        {
            "ioc_value": "194.59.31.142:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:29",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864987": [
        {
            "ioc_value": "194.59.31.142:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:29",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864985": [
        {
            "ioc_value": "185.139.228.93:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:15",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864984": [
        {
            "ioc_value": "185.103.167.150:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:12",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864983": [
        {
            "ioc_value": "18.178.127.205:21672",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:11",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864982": [
        {
            "ioc_value": "18.139.36.190:24610",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:44:10",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864981": [
        {
            "ioc_value": "172.96.137.123:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:44:04",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864980": [
        {
            "ioc_value": "154.215.14.139:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864979": [
        {
            "ioc_value": "132.226.72.148:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:26",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864976": [
        {
            "ioc_value": "118.107.46.177:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864977": [
        {
            "ioc_value": "118.107.46.177:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864978": [
        {
            "ioc_value": "118.107.46.204:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-30 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864975": [
        {
            "ioc_value": "107.175.32.45:8761",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864974": [
        {
            "ioc_value": "104.207.90.244:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-30 19:43:12",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864973": [
        {
            "ioc_value": "103.53.80.201:3312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 19:43:09",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864706": [
        {
            "ioc_value": "93.152.223.221:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-30 09:46:46",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864705": [
        {
            "ioc_value": "51.79.185.253:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:19",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864704": [
        {
            "ioc_value": "50.114.184.63:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:18",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864703": [
        {
            "ioc_value": "50.114.184.63:442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:46:17",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864702": [
        {
            "ioc_value": "46.151.182.16:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 09:46:11",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864701": [
        {
            "ioc_value": "27.124.36.151:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:45:43",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864700": [
        {
            "ioc_value": "217.60.241.73:7011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-30 09:45:35",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864699": [
        {
            "ioc_value": "209.99.190.23:45001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:44:46",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864698": [
        {
            "ioc_value": "2.27.248.116:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-30 09:44:36",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864697": [
        {
            "ioc_value": "176.65.148.198:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:44:08",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864696": [
        {
            "ioc_value": "173.199.70.174:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-30 09:44:06",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864694": [
        {
            "ioc_value": "144.172.93.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-30 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864693": [
        {
            "ioc_value": "103.148.58.8:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1864665": [
        {
            "ioc_value": "195.177.94.109:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:33",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864666": [
        {
            "ioc_value": "195.177.94.109:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:33",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864673": [
        {
            "ioc_value": "103.148.58.10:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:33",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864645": [
        {
            "ioc_value": "188.209.158.220:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:32",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864649": [
        {
            "ioc_value": "184.174.20.138:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:32",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864652": [
        {
            "ioc_value": "85.11.167.61:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:32",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864643": [
        {
            "ioc_value": "188.209.158.220:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:31",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864644": [
        {
            "ioc_value": "188.209.158.220:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-30 09:34:31",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1864479": [
        {
            "ioc_value": "147.93.62.224:7527",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-30 08:53:38",
            "last_seen_utc": "2026-08-10 23:40:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "91b8bca4002c9ac9274dd008d8155424,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1863982": [
        {
            "ioc_value": "arco-iris.tms-muenster.de",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-07-30 07:01:37",
            "last_seen_utc": "2026-08-10 09:00:35",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "",
            "tags": "Base,c2,ClickFix,etherhiding",
            "anonymous": 0,
            "reporter": "varysz"
        }
    ],
    "1863827": [
        {
            "ioc_value": "156.224.18.21:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 23:46:20",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863825": [
        {
            "ioc_value": "qrcjab.rsfoodproducts.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-29 23:34:06",
            "last_seen_utc": "2026-08-10 05:25:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0x0cd5,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1863594": [
        {
            "ioc_value": "92.118.39.95:3043",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-29 19:46:26",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863593": [
        {
            "ioc_value": "91.199.133.133:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-29 19:46:24",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863592": [
        {
            "ioc_value": "78.153.149.82:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-29 19:46:13",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863590": [
        {
            "ioc_value": "67.210.97.40:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:46:10",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863591": [
        {
            "ioc_value": "67.210.97.40:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:46:10",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863589": [
        {
            "ioc_value": "57.129.92.151:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-29 19:46:04",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863587": [
        {
            "ioc_value": "51.79.185.253:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:46:01",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863588": [
        {
            "ioc_value": "51.79.185.253:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:46:01",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863586": [
        {
            "ioc_value": "45.195.8.67:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-29 19:45:46",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863585": [
        {
            "ioc_value": "43.213.254.221:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:45:41",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863583": [
        {
            "ioc_value": "27.124.36.151:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:45:30",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863584": [
        {
            "ioc_value": "27.124.36.151:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:45:30",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863579": [
        {
            "ioc_value": "194.59.31.51:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:44:28",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863580": [
        {
            "ioc_value": "195.20.17.146:56776",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:44:28",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863578": [
        {
            "ioc_value": "194.59.31.51:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 19:44:27",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863577": [
        {
            "ioc_value": "192.71.244.238:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:44:25",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863576": [
        {
            "ioc_value": "192.253.245.178:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-29 19:44:24",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863575": [
        {
            "ioc_value": "185.212.128.207:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-29 19:44:16",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863574": [
        {
            "ioc_value": "185.174.102.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:44:15",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863573": [
        {
            "ioc_value": "178.16.53.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:44:08",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863572": [
        {
            "ioc_value": "172.86.89.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:44:02",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863571": [
        {
            "ioc_value": "162.216.231.230:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:43:54",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863570": [
        {
            "ioc_value": "155.2.192.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:45",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863569": [
        {
            "ioc_value": "154.194.50.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863568": [
        {
            "ioc_value": "149.56.30.94:3122",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-29 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863567": [
        {
            "ioc_value": "142.93.52.11:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 19:43:33",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863566": [
        {
            "ioc_value": "130.12.182.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:26",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863563": [
        {
            "ioc_value": "104.239.66.154:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863564": [
        {
            "ioc_value": "104.239.66.154:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863565": [
        {
            "ioc_value": "104.239.66.154:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863562": [
        {
            "ioc_value": "103.97.131.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 19:43:12",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863471": [
        {
            "ioc_value": "134.209.42.122:9895",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-29 17:41:00",
            "last_seen_utc": "2026-08-11 03:10:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "6ed07eee8b090ad8c77052912c8a29a6,c2,remus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1863378": [
        {
            "ioc_value": "14.225.212.124:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 11:47:01",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863346": [
        {
            "ioc_value": "93.152.223.222:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:46:12",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863347": [
        {
            "ioc_value": "93.152.223.224:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:46:12",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863345": [
        {
            "ioc_value": "86.106.119.24:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:46:05",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863344": [
        {
            "ioc_value": "84.201.20.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:46:02",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863341": [
        {
            "ioc_value": "67.210.97.40:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:45:54",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863340": [
        {
            "ioc_value": "43.206.219.14:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 09:45:29",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863339": [
        {
            "ioc_value": "23.94.252.80:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-29 09:45:17",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863337": [
        {
            "ioc_value": "195.177.94.11:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:44:21",
            "last_seen_utc": "2026-08-11 02:44:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863336": [
        {
            "ioc_value": "193.233.198.62:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863335": [
        {
            "ioc_value": "178.16.53.65:1907",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-29 09:44:01",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863333": [
        {
            "ioc_value": "168.222.97.120:1447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 09:43:54",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863334": [
        {
            "ioc_value": "169.58.50.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-29 09:43:54",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863332": [
        {
            "ioc_value": "167.148.41.137:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:43:52",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863329": [
        {
            "ioc_value": "15.235.151.49:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:43:36",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863330": [
        {
            "ioc_value": "15.235.151.49:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:43:36",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863331": [
        {
            "ioc_value": "15.235.151.49:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 09:43:36",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863315": [
        {
            "ioc_value": "94.26.3.166:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:54",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863313": [
        {
            "ioc_value": "93.152.221.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:52",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863314": [
        {
            "ioc_value": "94.154.32.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:52",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863312": [
        {
            "ioc_value": "91.92.40.56:9267",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:50",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863311": [
        {
            "ioc_value": "89.213.118.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:48",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863310": [
        {
            "ioc_value": "64.224.17.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:34",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863309": [
        {
            "ioc_value": "51.79.185.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:29",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863308": [
        {
            "ioc_value": "5.253.86.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:27",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863305": [
        {
            "ioc_value": "45.89.48.12:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:22",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863306": [
        {
            "ioc_value": "45.89.48.12:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:22",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863307": [
        {
            "ioc_value": "45.89.48.12:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:22",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863304": [
        {
            "ioc_value": "45.192.211.63:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:16",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863301": [
        {
            "ioc_value": "45.157.233.124:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:15",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863302": [
        {
            "ioc_value": "45.157.233.124:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:15",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863303": [
        {
            "ioc_value": "45.157.233.124:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:15",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863300": [
        {
            "ioc_value": "45.153.34.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:14",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863299": [
        {
            "ioc_value": "27.124.36.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:59:00",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863298": [
        {
            "ioc_value": "27.124.36.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:59",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863295": [
        {
            "ioc_value": "217.156.122.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:52",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863296": [
        {
            "ioc_value": "217.60.195.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:52",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863297": [
        {
            "ioc_value": "217.60.195.167:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:52",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863294": [
        {
            "ioc_value": "209.99.190.23:55012",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:17",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863292": [
        {
            "ioc_value": "194.9.6.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:05",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863255": [
        {
            "ioc_value": "193.164.5.4:9991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:02",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863241": [
        {
            "ioc_value": "192.229.115.162:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:01",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863230": [
        {
            "ioc_value": "192.229.115.154:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:00",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863234": [
        {
            "ioc_value": "192.229.115.156:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:00",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863237": [
        {
            "ioc_value": "192.229.115.162:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:58:00",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863164": [
        {
            "ioc_value": "185.247.208.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:56",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863169": [
        {
            "ioc_value": "185.254.99.153:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:56",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863089": [
        {
            "ioc_value": "185.174.101.235:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:52",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863051": [
        {
            "ioc_value": "181.215.242.78:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:48",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863052": [
        {
            "ioc_value": "181.215.242.84:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:48",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863050": [
        {
            "ioc_value": "178.211.155.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:46",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863049": [
        {
            "ioc_value": "178.16.53.65:2828",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:45",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863048": [
        {
            "ioc_value": "176.96.136.230:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:44",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863047": [
        {
            "ioc_value": "176.96.136.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:43",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863045": [
        {
            "ioc_value": "163.5.210.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:36",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863046": [
        {
            "ioc_value": "167.148.41.137:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:36",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863044": [
        {
            "ioc_value": "160.119.69.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:33",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863043": [
        {
            "ioc_value": "158.94.210.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:32",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863041": [
        {
            "ioc_value": "151.242.63.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:21",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863042": [
        {
            "ioc_value": "151.242.97.15:56831",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:21",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1863040": [
        {
            "ioc_value": "140.228.29.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:57:12",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862853": [
        {
            "ioc_value": "103.114.218.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 08:56:51",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861775": [
        {
            "ioc_value": "176.96.136.230:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:09",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861777": [
        {
            "ioc_value": "45.192.211.7:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:09",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861778": [
        {
            "ioc_value": "103.68.109.13:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:08",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861780": [
        {
            "ioc_value": "176.96.136.230:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-29 07:42:08",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "PureRat",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861784": [
        {
            "ioc_value": "130.94.7.119:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 07:42:07",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsynRat,Server",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1861793": [
        {
            "ioc_value": "104.200.67.224:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-29 07:41:53",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsynRat,Server",
            "anonymous": 0,
            "reporter": "RacWatchin8872"
        }
    ],
    "1862621": [
        {
            "ioc_value": "154.12.94.16:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 07:32:16",
            "last_seen_utc": "2026-08-10 06:28:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862620": [
        {
            "ioc_value": "117.72.199.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 07:32:11",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862618": [
        {
            "ioc_value": "154.12.94.16:2087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 07:31:57",
            "last_seen_utc": "2026-08-10 08:08:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1862523": [
        {
            "ioc_value": "102.204.223.106:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-29 05:46:21",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861820": [
        {
            "ioc_value": "89.213.118.199:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-28 19:46:24",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861821": [
        {
            "ioc_value": "89.213.118.199:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-28 19:46:24",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861822": [
        {
            "ioc_value": "89.213.118.199:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-28 19:46:24",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861819": [
        {
            "ioc_value": "45.62.170.226:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:50",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861818": [
        {
            "ioc_value": "31.58.179.22:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-28 19:45:36",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861817": [
        {
            "ioc_value": "31.57.184.154:2504",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:34",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861816": [
        {
            "ioc_value": "23.94.148.17:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:30",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861815": [
        {
            "ioc_value": "217.60.241.88:7008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:45:25",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861814": [
        {
            "ioc_value": "204.44.69.230:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:44:36",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861813": [
        {
            "ioc_value": "194.59.30.53:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:44:26",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861812": [
        {
            "ioc_value": "172.111.232.195:7775",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-28 19:44:00",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861811": [
        {
            "ioc_value": "130.94.7.119:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:43:27",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861810": [
        {
            "ioc_value": "104.248.185.92:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-28 19:43:15",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861809": [
        {
            "ioc_value": "104.200.67.224:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861744": [
        {
            "ioc_value": "45.192.211.7:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861745": [
        {
            "ioc_value": "45.192.211.7:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861746": [
        {
            "ioc_value": "80.76.49.3:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:29",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861736": [
        {
            "ioc_value": "45.119.98.140:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861737": [
        {
            "ioc_value": "45.119.98.140:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861738": [
        {
            "ioc_value": "45.119.98.140:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861739": [
        {
            "ioc_value": "45.192.211.19:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861740": [
        {
            "ioc_value": "45.192.211.19:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861741": [
        {
            "ioc_value": "45.192.211.19:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861742": [
        {
            "ioc_value": "45.192.211.63:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861743": [
        {
            "ioc_value": "45.192.211.77:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:28",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861722": [
        {
            "ioc_value": "193.233.198.62:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861730": [
        {
            "ioc_value": "45.119.98.111:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861731": [
        {
            "ioc_value": "45.119.98.111:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861732": [
        {
            "ioc_value": "45.119.98.111:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:27",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861710": [
        {
            "ioc_value": "108.187.4.116:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861711": [
        {
            "ioc_value": "108.187.4.145:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861712": [
        {
            "ioc_value": "108.187.4.145:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861713": [
        {
            "ioc_value": "108.187.4.145:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861714": [
        {
            "ioc_value": "112.121.176.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861715": [
        {
            "ioc_value": "112.121.176.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861717": [
        {
            "ioc_value": "112.121.176.5:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861718": [
        {
            "ioc_value": "112.121.176.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:26",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861705": [
        {
            "ioc_value": "103.68.109.13:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861706": [
        {
            "ioc_value": "103.68.109.13:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861707": [
        {
            "ioc_value": "104.164.46.39:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861708": [
        {
            "ioc_value": "108.187.4.116:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861709": [
        {
            "ioc_value": "108.187.4.116:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-28 16:59:25",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,PureRAT",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861640": [
        {
            "ioc_value": "phiplips.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-28 16:54:50",
            "last_seen_utc": "2026-08-10 21:10:51",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": "https://infosec.exchange/@monitorsg/116998473477272648",
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1861573": [
        {
            "ioc_value": "griffihhs.click",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.kongtuke",
            "malware_alias": "TAG-124,js.LandUpdate808",
            "malware_printable": "KongTuke",
            "first_seen_utc": "2026-07-28 13:19:49",
            "last_seen_utc": "2026-08-11 03:10:04",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "KongTuke",
            "anonymous": 0,
            "reporter": "monitorsg"
        }
    ],
    "1861522": [
        {
            "ioc_value": "96.126.176.92:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:46:46",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861521": [
        {
            "ioc_value": "93.152.223.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:46:44",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861520": [
        {
            "ioc_value": "49.235.50.231:14486",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-28 09:46:12",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861519": [
        {
            "ioc_value": "46.246.6.7:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-28 09:46:11",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861518": [
        {
            "ioc_value": "46.151.182.76:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:46:09",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861516": [
        {
            "ioc_value": "23.94.252.87:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:45:42",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861517": [
        {
            "ioc_value": "24.244.73.237:40056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-28 09:45:42",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861515": [
        {
            "ioc_value": "23.94.252.55:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-28 09:45:41",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861514": [
        {
            "ioc_value": "217.165.57.247:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:45:35",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861513": [
        {
            "ioc_value": "207.246.75.30:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:44:46",
            "last_seen_utc": "2026-08-11 02:44:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861512": [
        {
            "ioc_value": "206.189.167.120:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:44:45",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861511": [
        {
            "ioc_value": "2.27.63.244:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:44:40",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861510": [
        {
            "ioc_value": "178.16.53.68:3009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:44:13",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861509": [
        {
            "ioc_value": "158.94.210.161:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-28 09:43:56",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861508": [
        {
            "ioc_value": "157.245.228.139:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-28 09:43:54",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861507": [
        {
            "ioc_value": "130.12.182.249:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-28 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861477": [
        {
            "ioc_value": "https://193.111.117.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-28 08:37:26",
            "last_seen_utc": "2026-08-11 03:29:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,f3f52941b868d54e7936351d349364fb,loader,stealer,Vidar",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1861464": [
        {
            "ioc_value": "106.14.243.66:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-28 07:23:35",
            "last_seen_utc": "2026-08-10 06:28:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861354": [
        {
            "ioc_value": "158.94.211.163:24443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-27 23:45:57",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861355": [
        {
            "ioc_value": "159.94.211.163:24443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-27 23:45:57",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1861326": [
        {
            "ioc_value": "189.249.193.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-27 22:05:05",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1861181": [
        {
            "ioc_value": "36.139.36.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 21:05:07",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "adaptix",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860744": [
        {
            "ioc_value": "46.151.182.76:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:45:24",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860743": [
        {
            "ioc_value": "204.44.69.230:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:44:20",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860742": [
        {
            "ioc_value": "155.138.203.207:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:43:38",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860740": [
        {
            "ioc_value": "137.220.155.44:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-27 19:43:24",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860741": [
        {
            "ioc_value": "137.220.155.44:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-27 19:43:24",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860739": [
        {
            "ioc_value": "130.12.182.249:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860738": [
        {
            "ioc_value": "130.12.182.249:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860737": [
        {
            "ioc_value": "109.122.18.38:5552",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860713": [
        {
            "ioc_value": "173.249.212.231:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 18:05:07",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860683": [
        {
            "ioc_value": "ovq3ncff.eachway-multiplier.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-27 15:55:43",
            "last_seen_utc": "2026-08-10 01:05:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,mac-0x68dc,macos",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860612": [
        {
            "ioc_value": "node3.meadowrhythm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.revstealer",
            "malware_alias": null,
            "malware_printable": "RevStealer",
            "first_seen_utc": "2026-07-27 15:30:07",
            "last_seen_utc": "2026-08-09 09:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "exe,revstealer",
            "anonymous": 0,
            "reporter": "Myrtus0x0"
        }
    ],
    "1860583": [
        {
            "ioc_value": "yvesrxkzcdxycnarab.crownconnectpk.com",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-27 15:21:52",
            "last_seen_utc": "2026-08-11 01:26:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ClearFake,win-0xa770,windows",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860536": [
        {
            "ioc_value": "160.119.71.120:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-27 13:42:57",
            "last_seen_utc": "2026-08-11 03:17:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AISURU",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860247": [
        {
            "ioc_value": "193.233.198.62:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-07-27 13:25:21",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1860224": [
        {
            "ioc_value": "47.103.214.7:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-27 11:46:45",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860093": [
        {
            "ioc_value": "94.154.32.56:27221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:46:11",
            "last_seen_utc": "2026-08-11 02:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860092": [
        {
            "ioc_value": "94.154.32.56:27220",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:46:10",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860091": [
        {
            "ioc_value": "91.92.40.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-27 09:46:09",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860090": [
        {
            "ioc_value": "84.200.154.216:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-27 09:46:01",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860089": [
        {
            "ioc_value": "46.151.182.76:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:45:41",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860088": [
        {
            "ioc_value": "45.59.160.198:52203",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:45:36",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860087": [
        {
            "ioc_value": "204.44.69.230:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-27 09:44:29",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860086": [
        {
            "ioc_value": "2.26.26.153:43216",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 09:44:23",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860085": [
        {
            "ioc_value": "194.233.80.96:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 09:44:20",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860084": [
        {
            "ioc_value": "172.245.232.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-27 09:43:55",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1860083": [
        {
            "ioc_value": "130.12.182.184:1339",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-27 09:43:24",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859700": [
        {
            "ioc_value": "141.255.162.234:37422",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 23:45:57",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859680": [
        {
            "ioc_value": "47.113.98.42:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:46:16",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859678": [
        {
            "ioc_value": "dns1.dreamls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:45:45",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859679": [
        {
            "ioc_value": "dns2.dreamls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-26 21:45:45",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1859195": [
        {
            "ioc_value": "fresh-produce.co.uk",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "js.clearfake",
            "malware_alias": null,
            "malware_printable": "ClearFake",
            "first_seen_utc": "2026-07-26 20:17:53",
            "last_seen_utc": "2026-08-09 04:21:03",
            "confidence_level": 50,
            "is_compromised": true,
            "reference": "",
            "tags": "ClearFake,ClickFix",
            "anonymous": 0,
            "reporter": "skocherhan"
        }
    ],
    "1858981": [
        {
            "ioc_value": "93.152.221.140:1010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-26 19:45:49",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858980": [
        {
            "ioc_value": "2.27.248.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-26 19:44:16",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858979": [
        {
            "ioc_value": "192.162.199.143:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-26 19:44:08",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858978": [
        {
            "ioc_value": "176.65.149.209:3043",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-26 19:43:54",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858977": [
        {
            "ioc_value": "157.20.182.22:4442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-26 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857981": [
        {
            "ioc_value": "198.98.53.100:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-26 10:55:50",
            "last_seen_utc": "2026-08-10 05:50:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1858181": [
        {
            "ioc_value": "5.181.181.12:5443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-26 09:45:52",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858180": [
        {
            "ioc_value": "199.246.88.101:5432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-26 09:44:26",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1858179": [
        {
            "ioc_value": "103.67.163.201:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-26 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857979": [
        {
            "ioc_value": "54.178.100.27:8021",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-25 23:46:33",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857976": [
        {
            "ioc_value": "157.20.182.22:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 23:05:05",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1857725": [
        {
            "ioc_value": "82.158.88.41:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-25 19:46:06",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857724": [
        {
            "ioc_value": "46.246.12.2:6490",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-25 19:45:46",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857723": [
        {
            "ioc_value": "37.244.233.190:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-25 19:45:29",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857722": [
        {
            "ioc_value": "27.124.20.3:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:45:23",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857720": [
        {
            "ioc_value": "2.27.248.209:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:44:25",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857719": [
        {
            "ioc_value": "185.147.83.59:48321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:44:10",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857718": [
        {
            "ioc_value": "146.70.87.23:43225",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:43:34",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857717": [
        {
            "ioc_value": "144.208.127.87:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 19:43:33",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857716": [
        {
            "ioc_value": "141.255.164.33:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 19:43:29",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857715": [
        {
            "ioc_value": "103.67.163.201:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 19:43:11",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857363": [
        {
            "ioc_value": "38.54.89.235:6688",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-25 11:46:12",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857362": [
        {
            "ioc_value": "117.28.246.18:8067",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-25 11:45:55",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857246": [
        {
            "ioc_value": "198.98.53.100:9034",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-25 11:02:40",
            "last_seen_utc": "2026-08-09 13:23:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1857339": [
        {
            "ioc_value": "157.20.182.21:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 10:43:43",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857317": [
        {
            "ioc_value": "74.249.84.175:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:46:00",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857316": [
        {
            "ioc_value": "51.107.74.185:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:45:51",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857315": [
        {
            "ioc_value": "46.246.12.2:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-25 09:45:47",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857313": [
        {
            "ioc_value": "31.76.96.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 09:45:30",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857314": [
        {
            "ioc_value": "31.76.96.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-25 09:45:30",
            "last_seen_utc": "2026-08-11 02:45:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857311": [
        {
            "ioc_value": "27.124.20.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:45:27",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857312": [
        {
            "ioc_value": "27.124.20.6:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:45:27",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857310": [
        {
            "ioc_value": "207.57.123.129:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:42",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857308": [
        {
            "ioc_value": "2.27.28.207:42153",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:36",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857309": [
        {
            "ioc_value": "2.27.29.171:42216",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:44:36",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857307": [
        {
            "ioc_value": "196.251.107.131:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857306": [
        {
            "ioc_value": "182.161.12.169:8050",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-25 09:44:18",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857305": [
        {
            "ioc_value": "146.103.38.224:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 09:43:31",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857304": [
        {
            "ioc_value": "144.172.118.84:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:43:30",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857303": [
        {
            "ioc_value": "119.28.212.86:44321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-25 09:43:20",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857302": [
        {
            "ioc_value": "103.67.163.201:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-25 09:43:10",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857015": [
        {
            "ioc_value": "209.200.246.194:34586",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-24 23:46:13",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1857014": [
        {
            "ioc_value": "103.193.150.74:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-24 23:45:54",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856912": [
        {
            "ioc_value": "87.251.64.204:63812",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-24 19:45:44",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856911": [
        {
            "ioc_value": "46.246.12.2:2512",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:45:23",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856910": [
        {
            "ioc_value": "45.11.59.152:43200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-24 19:45:13",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856909": [
        {
            "ioc_value": "38.60.220.51:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-24 19:45:10",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856908": [
        {
            "ioc_value": "23.94.252.7:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 19:44:59",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856907": [
        {
            "ioc_value": "2.27.248.80:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 19:44:16",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856906": [
        {
            "ioc_value": "193.93.194.42:57301",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-24 19:44:11",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856905": [
        {
            "ioc_value": "185.212.129.117:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-24 19:44:03",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856904": [
        {
            "ioc_value": "158.94.211.191:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856903": [
        {
            "ioc_value": "157.20.182.21:1992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856897": [
        {
            "ioc_value": "156.247.47.108:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856898": [
        {
            "ioc_value": "156.247.47.108:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856899": [
        {
            "ioc_value": "156.247.47.109:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856900": [
        {
            "ioc_value": "156.247.47.109:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856901": [
        {
            "ioc_value": "156.247.47.110:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856902": [
        {
            "ioc_value": "156.247.47.110:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856895": [
        {
            "ioc_value": "156.247.47.106:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:38",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856896": [
        {
            "ioc_value": "156.247.47.106:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 19:43:38",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856894": [
        {
            "ioc_value": "151.236.21.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-24 19:43:33",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856893": [
        {
            "ioc_value": "143.110.132.139:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-24 19:43:28",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856890": [
        {
            "ioc_value": "13.143.139.239:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856891": [
        {
            "ioc_value": "13.143.139.239:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856892": [
        {
            "ioc_value": "13.143.139.239:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856814": [
        {
            "ioc_value": "111.228.62.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-24 15:05:06",
            "last_seen_utc": "2026-08-10 06:28:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1856791": [
        {
            "ioc_value": "https://sup.merahsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-24 13:50:06",
            "last_seen_utc": "2026-08-11 03:25:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1856790": [
        {
            "ioc_value": "sup.merahsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-24 13:50:05",
            "last_seen_utc": "2026-08-11 03:25:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1856711": [
        {
            "ioc_value": "79.110.49.148:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 09:46:45",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856709": [
        {
            "ioc_value": "79.110.49.148:1009",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 09:46:44",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856710": [
        {
            "ioc_value": "79.110.49.148:60",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 09:46:44",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856708": [
        {
            "ioc_value": "23.94.145.121:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-24 09:45:54",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856707": [
        {
            "ioc_value": "198.211.101.176:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-07-24 09:44:39",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856706": [
        {
            "ioc_value": "178.16.54.132:1987",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-24 09:44:15",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856705": [
        {
            "ioc_value": "157.20.182.22:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 09:43:56",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856704": [
        {
            "ioc_value": "157.20.182.21:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-24 09:43:55",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856675": [
        {
            "ioc_value": "42.193.22.177:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-24 07:25:20",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856638": [
        {
            "ioc_value": "198.98.53.100:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-24 06:20:07",
            "last_seen_utc": "2026-08-10 17:14:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Aisuru,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1856292": [
        {
            "ioc_value": "93.152.224.94:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:46:19",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856291": [
        {
            "ioc_value": "93.152.223.159:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:46:18",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856290": [
        {
            "ioc_value": "45.207.222.132:15847",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-23 19:45:40",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856289": [
        {
            "ioc_value": "38.255.43.22:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856288": [
        {
            "ioc_value": "2.27.248.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:28",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856285": [
        {
            "ioc_value": "2.27.248.232:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856286": [
        {
            "ioc_value": "2.27.248.236:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856287": [
        {
            "ioc_value": "2.27.248.72:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 19:44:27",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856284": [
        {
            "ioc_value": "155.117.232.184:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-23 19:43:44",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856283": [
        {
            "ioc_value": "104.239.66.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856216": [
        {
            "ioc_value": "8.135.47.140:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:56",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856215": [
        {
            "ioc_value": "38.244.52.101:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:43",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856214": [
        {
            "ioc_value": "102.204.223.106:2053",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:20",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856213": [
        {
            "ioc_value": "www.ai2.qzz.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:18",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1856212": [
        {
            "ioc_value": "cloud-svc.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 15:46:13",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855969": [
        {
            "ioc_value": "64.224.17.167:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:45:56",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855967": [
        {
            "ioc_value": "2.27.160.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 09:44:27",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855968": [
        {
            "ioc_value": "2.27.248.234:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-23 09:44:27",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855966": [
        {
            "ioc_value": "178.156.186.93:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-23 09:44:03",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855964": [
        {
            "ioc_value": "172.239.45.42:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-23 09:43:57",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855965": [
        {
            "ioc_value": "172.245.27.162:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:43:57",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855963": [
        {
            "ioc_value": "157.20.182.22:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:43:48",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855962": [
        {
            "ioc_value": "157.20.182.21:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:43:47",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855961": [
        {
            "ioc_value": "151.243.145.220:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-23 09:43:39",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855960": [
        {
            "ioc_value": "137.220.158.10:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-23 09:43:28",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855959": [
        {
            "ioc_value": "130.17.9.209:36806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-07-23 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855958": [
        {
            "ioc_value": "109.122.18.70:20703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-23 09:43:18",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855925": [
        {
            "ioc_value": "64.177.113.11:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-23 08:05:07",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855923": [
        {
            "ioc_value": "174.138.9.149:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-23 08:05:05",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855877": [
        {
            "ioc_value": "cdn.pixelcss.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-23 05:46:03",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855460": [
        {
            "ioc_value": "43.228.157.252:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:45:15",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855459": [
        {
            "ioc_value": "43.213.142.102:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 19:45:14",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855457": [
        {
            "ioc_value": "172.245.27.162:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:50",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855458": [
        {
            "ioc_value": "172.245.27.162:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:50",
            "last_seen_utc": "2026-08-11 02:44:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855456": [
        {
            "ioc_value": "165.22.129.73:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 19:43:47",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855454": [
        {
            "ioc_value": "157.20.182.21:4442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855455": [
        {
            "ioc_value": "157.20.182.22:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855453": [
        {
            "ioc_value": "137.184.163.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 19:43:25",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855452": [
        {
            "ioc_value": "134.209.114.97:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-22 19:43:24",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855451": [
        {
            "ioc_value": "12.187.175.73:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855450": [
        {
            "ioc_value": "107.175.114.221:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855382": [
        {
            "ioc_value": "43.134.38.218:4543",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 17:05:52",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1855249": [
        {
            "ioc_value": "45.142.141.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-22 09:45:30",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855248": [
        {
            "ioc_value": "23.94.197.120:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:45:17",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855247": [
        {
            "ioc_value": "203.99.149.78:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:44:26",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855246": [
        {
            "ioc_value": "20.200.61.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:44:24",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855245": [
        {
            "ioc_value": "192.227.219.71:3341",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:44:15",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855244": [
        {
            "ioc_value": "167.160.190.182:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-22 09:43:50",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855243": [
        {
            "ioc_value": "157.20.182.21:1338",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:43:45",
            "last_seen_utc": "2026-08-11 02:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855242": [
        {
            "ioc_value": "157.20.182.21:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:43:44",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855241": [
        {
            "ioc_value": "147.50.253.241:4415",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 09:43:34",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855240": [
        {
            "ioc_value": "137.220.158.10:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-22 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855239": [
        {
            "ioc_value": "132.145.210.148:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855238": [
        {
            "ioc_value": "104.248.69.160:65000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-22 09:43:14",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855226": [
        {
            "ioc_value": "217.60.241.34:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 08:55:56",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/40b95ef52169126b3732d14479f1497715ec0f5bf1bc6fd0104188f7911f5fef/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855227": [
        {
            "ioc_value": "217.60.241.34:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 08:55:56",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/40b95ef52169126b3732d14479f1497715ec0f5bf1bc6fd0104188f7911f5fef/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855221": [
        {
            "ioc_value": "217.60.241.34:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-22 08:50:03",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855202": [
        {
            "ioc_value": "http://vriclactrina.cz/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.smokeloader",
            "malware_alias": "Dofoil,Sharik,Smoke,Smoke Loader",
            "malware_printable": "SmokeLoader",
            "first_seen_utc": "2026-07-22 08:06:59",
            "last_seen_utc": "2026-08-11 02:35:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,SmokeLoader",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1855047": [
        {
            "ioc_value": "86.48.16.94:30100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 19:46:20",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855046": [
        {
            "ioc_value": "85.208.69.45:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-21 19:46:19",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855045": [
        {
            "ioc_value": "45.59.120.31:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-21 19:45:46",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855044": [
        {
            "ioc_value": "45.142.141.139:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 19:45:42",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855043": [
        {
            "ioc_value": "43.213.171.100:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:41",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855041": [
        {
            "ioc_value": "43.213.142.102:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:40",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855042": [
        {
            "ioc_value": "43.213.171.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:40",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855039": [
        {
            "ioc_value": "34.106.101.107:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855040": [
        {
            "ioc_value": "34.28.220.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855038": [
        {
            "ioc_value": "2.27.122.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-21 19:44:32",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855037": [
        {
            "ioc_value": "159.203.187.219:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-21 19:43:52",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855036": [
        {
            "ioc_value": "147.50.253.241:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-21 19:43:38",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855035": [
        {
            "ioc_value": "141.253.195.133:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:43:32",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1855034": [
        {
            "ioc_value": "132.145.210.148:11235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-21 19:43:28",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854871": [
        {
            "ioc_value": "185.33.86.141:29292",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-21 09:44:16",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854508": [
        {
            "ioc_value": "94.154.43.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-20 19:45:56",
            "last_seen_utc": "2026-08-11 02:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854507": [
        {
            "ioc_value": "77.237.114.150:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-20 19:45:43",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854506": [
        {
            "ioc_value": "46.29.162.159:52310",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:45:29",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854505": [
        {
            "ioc_value": "23.94.197.120:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 19:45:07",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854504": [
        {
            "ioc_value": "220.154.3.197:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:45:02",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854503": [
        {
            "ioc_value": "203.83.238.164:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:44:22",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854502": [
        {
            "ioc_value": "2.27.248.61:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-20 19:44:19",
            "last_seen_utc": "2026-08-11 02:44:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854501": [
        {
            "ioc_value": "181.234.136.109:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-20 19:43:58",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854500": [
        {
            "ioc_value": "176.12.79.82:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:54",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854498": [
        {
            "ioc_value": "151.243.101.44:21343",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:37",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854496": [
        {
            "ioc_value": "14.22.75.6:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854497": [
        {
            "ioc_value": "14.22.75.6:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 19:43:29",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854495": [
        {
            "ioc_value": "12.202.180.13:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854201": [
        {
            "ioc_value": "89.124.104.192:49999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-20 09:45:58",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854200": [
        {
            "ioc_value": "220.154.3.197:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:45:09",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854198": [
        {
            "ioc_value": "203.83.238.164:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854199": [
        {
            "ioc_value": "203.83.238.164:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:44:25",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854197": [
        {
            "ioc_value": "192.227.219.71:34471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 09:44:15",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854196": [
        {
            "ioc_value": "185.212.131.28:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854195": [
        {
            "ioc_value": "185.212.128.155:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:44:07",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854193": [
        {
            "ioc_value": "169.58.12.228:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-20 09:43:51",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854192": [
        {
            "ioc_value": "154.83.186.39:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-20 09:43:39",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854191": [
        {
            "ioc_value": "147.93.191.75:20800",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854190": [
        {
            "ioc_value": "147.93.191.75:20700",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-20 09:43:34",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1854188": [
        {
            "ioc_value": "103.185.249.13:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-20 09:43:11",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853904": [
        {
            "ioc_value": "89.223.24.227:52709",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-19 19:45:39",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853903": [
        {
            "ioc_value": "213.160.77.221:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:44:23",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853902": [
        {
            "ioc_value": "209.160.115.136:8624",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-19 19:44:19",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853901": [
        {
            "ioc_value": "178.105.144.206:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 19:43:50",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853900": [
        {
            "ioc_value": "159.65.232.209:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853899": [
        {
            "ioc_value": "157.230.235.215:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-19 19:43:40",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853898": [
        {
            "ioc_value": "14.22.75.6:8766",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-19 19:43:26",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853839": [
        {
            "ioc_value": "https://qar.arizonafamilylawfirm.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 17:27:03",
            "last_seen_utc": "2026-08-11 03:24:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "bhipk,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853840": [
        {
            "ioc_value": "qar.arizonafamilylawfirm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-19 17:27:03",
            "last_seen_utc": "2026-08-11 03:24:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "bhipk,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853729": [
        {
            "ioc_value": "154.12.85.75:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-19 10:16:42",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853718": [
        {
            "ioc_value": "91.92.47.95:56999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-19 09:46:24",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853717": [
        {
            "ioc_value": "185.147.83.58:64213",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-19 09:44:11",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853568": [
        {
            "ioc_value": "38.76.169.75:870",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 23:46:07",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853567": [
        {
            "ioc_value": "130.94.34.66:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 23:45:54",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853534": [
        {
            "ioc_value": "64.89.161.190:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:45:54",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853533": [
        {
            "ioc_value": "5.35.91.124:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-18 19:45:46",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853531": [
        {
            "ioc_value": "198.23.185.95:20100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:44:24",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853532": [
        {
            "ioc_value": "198.23.185.95:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:44:24",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853530": [
        {
            "ioc_value": "193.93.193.135:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-18 19:44:20",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853529": [
        {
            "ioc_value": "147.93.191.75:20100",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 19:43:34",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853528": [
        {
            "ioc_value": "144.172.88.233:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-18 19:43:31",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853428": [
        {
            "ioc_value": "103.86.65.202:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 17:31:55",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853338": [
        {
            "ioc_value": "159.94.211.163:14443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 09:47:35",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853337": [
        {
            "ioc_value": "158.94.211.163:14443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-18 09:47:34",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853335": [
        {
            "ioc_value": "46.246.12.19:2703",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 09:46:23",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853334": [
        {
            "ioc_value": "45.55.98.175:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-18 09:46:14",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853333": [
        {
            "ioc_value": "31.57.93.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-18 09:45:59",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853331": [
        {
            "ioc_value": "217.217.97.111:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-18 09:45:49",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853330": [
        {
            "ioc_value": "2.59.132.84:7434",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 09:44:45",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853329": [
        {
            "ioc_value": "198.23.185.95:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-18 09:44:41",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1853328": [
        {
            "ioc_value": "138.124.90.26:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-18 09:43:33",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852991": [
        {
            "ioc_value": "45.194.17.39:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-17 21:46:50",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852912": [
        {
            "ioc_value": "20.2.87.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 21:05:07",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852892": [
        {
            "ioc_value": "62.109.10.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 19:45:58",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852890": [
        {
            "ioc_value": "46.225.160.243:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-17 19:45:49",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852891": [
        {
            "ioc_value": "46.246.82.7:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-17 19:45:49",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852889": [
        {
            "ioc_value": "221.212.219.56:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-17 19:45:23",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852888": [
        {
            "ioc_value": "207.180.29.217:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:34",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852887": [
        {
            "ioc_value": "198.23.185.95:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:27",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852886": [
        {
            "ioc_value": "181.235.4.60:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:44:05",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852885": [
        {
            "ioc_value": "178.83.226.199:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-17 19:44:03",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852884": [
        {
            "ioc_value": "157.20.182.17:1665",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:43:48",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852883": [
        {
            "ioc_value": "15.235.149.212:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-17 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852881": [
        {
            "ioc_value": "147.93.191.75:50",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852882": [
        {
            "ioc_value": "149.104.110.202:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852880": [
        {
            "ioc_value": "104.249.10.121:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-17 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852879": [
        {
            "ioc_value": "104.168.0.147:1989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-17 19:43:15",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852872": [
        {
            "ioc_value": "175.43.223.223:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-17 18:05:06",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1852802": [
        {
            "ioc_value": "https://okx.kliksm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-17 11:10:08",
            "last_seen_utc": "2026-08-11 03:24:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1852801": [
        {
            "ioc_value": "okx.kliksm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-17 11:10:07",
            "last_seen_utc": "2026-08-11 03:24:34",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1852649": [
        {
            "ioc_value": "80.240.21.145:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:46:46",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852648": [
        {
            "ioc_value": "64.177.120.228:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:46:37",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852647": [
        {
            "ioc_value": "5.200.192.159:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-16 19:46:28",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852646": [
        {
            "ioc_value": "45.32.90.122:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:46:15",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852645": [
        {
            "ioc_value": "43.225.157.146:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:46:09",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852644": [
        {
            "ioc_value": "217.60.241.10:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 19:45:50",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852643": [
        {
            "ioc_value": "199.247.22.101:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:44:42",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852642": [
        {
            "ioc_value": "194.32.142.225:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-16 19:44:38",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852641": [
        {
            "ioc_value": "188.166.40.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 19:44:30",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852640": [
        {
            "ioc_value": "154.19.229.197:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-16 19:43:49",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852491": [
        {
            "ioc_value": "203.91.75.89:5005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 09:47:53",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852490": [
        {
            "ioc_value": "85.120.217.235:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:46:58",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852489": [
        {
            "ioc_value": "64.89.161.190:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:46",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852486": [
        {
            "ioc_value": "5.56.25.238:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:37",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852487": [
        {
            "ioc_value": "5.56.25.238:6723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:37",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852488": [
        {
            "ioc_value": "5.56.25.238:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:37",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852485": [
        {
            "ioc_value": "37.60.239.250:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:46:12",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852484": [
        {
            "ioc_value": "217.60.241.10:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:45:57",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852483": [
        {
            "ioc_value": "209.99.189.225:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:45:04",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852482": [
        {
            "ioc_value": "207.180.250.181:20300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:44:58",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852480": [
        {
            "ioc_value": "204.44.93.75:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-16 09:44:56",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852481": [
        {
            "ioc_value": "204.44.93.75:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-16 09:44:56",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852479": [
        {
            "ioc_value": "192.142.37.30:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:44:40",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852478": [
        {
            "ioc_value": "154.19.229.85:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-16 09:43:52",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852477": [
        {
            "ioc_value": "147.124.219.0:8805",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:43:47",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852475": [
        {
            "ioc_value": "109.123.230.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852476": [
        {
            "ioc_value": "109.123.230.199:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-16 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1852474": [
        {
            "ioc_value": "104.168.134.25:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-16 09:43:19",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851397": [
        {
            "ioc_value": "14.29.160.181:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-16 04:05:05",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1851315": [
        {
            "ioc_value": "107.174.254.62:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-15 21:46:16",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851289": [
        {
            "ioc_value": "64.23.182.12:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:46:03",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851290": [
        {
            "ioc_value": "64.89.160.127:2026",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:46:03",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851288": [
        {
            "ioc_value": "5.56.25.238:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:45:56",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851286": [
        {
            "ioc_value": "216.250.249.83:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:45:24",
            "last_seen_utc": "2026-08-11 02:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851287": [
        {
            "ioc_value": "216.250.249.83:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:45:24",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851284": [
        {
            "ioc_value": "204.44.93.75:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:44:38",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851285": [
        {
            "ioc_value": "204.44.93.75:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:44:38",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851283": [
        {
            "ioc_value": "185.212.131.22:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:44:19",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851282": [
        {
            "ioc_value": "185.115.164.59:7723",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:44:13",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851281": [
        {
            "ioc_value": "178.73.192.16:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 19:44:08",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851280": [
        {
            "ioc_value": "162.35.175.224:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 19:43:55",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851279": [
        {
            "ioc_value": "104.225.104.237:3020",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 19:43:16",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851278": [
        {
            "ioc_value": "104.168.134.25:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 19:43:15",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851277": [
        {
            "ioc_value": "103.83.86.48:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1851276": [
        {
            "ioc_value": "103.11.41.10:17328",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 19:43:06",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850972": [
        {
            "ioc_value": "82.47.101.76:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 09:46:24",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850971": [
        {
            "ioc_value": "74.0.32.137:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-15 09:46:18",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850969": [
        {
            "ioc_value": "216.250.254.245:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 09:45:31",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850967": [
        {
            "ioc_value": "213.152.186.188:18856",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 09:44:48",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850966": [
        {
            "ioc_value": "204.44.69.214:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:44:41",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850965": [
        {
            "ioc_value": "192.255.195.147:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:44:28",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850964": [
        {
            "ioc_value": "191.104.219.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-07-15 09:44:26",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850962": [
        {
            "ioc_value": "124.198.132.119:5220",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:43:27",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850961": [
        {
            "ioc_value": "104.225.104.237:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-15 09:43:17",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850960": [
        {
            "ioc_value": "103.11.41.10:62452",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:43:08",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850959": [
        {
            "ioc_value": "103.11.41.10:10443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-15 09:43:06",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850805": [
        {
            "ioc_value": "217.217.97.75:8787",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-15 05:20:03",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850746": [
        {
            "ioc_value": "206.119.178.109:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-14 21:46:37",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850712": [
        {
            "ioc_value": "87.232.83.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-14 19:46:04",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850711": [
        {
            "ioc_value": "85.206.168.238:4646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:46:01",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850710": [
        {
            "ioc_value": "64.89.161.190:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:45:50",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850709": [
        {
            "ioc_value": "45.74.7.107:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:45:34",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850708": [
        {
            "ioc_value": "45.155.69.254:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 19:45:31",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850707": [
        {
            "ioc_value": "217.60.241.10:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:45:13",
            "last_seen_utc": "2026-08-11 02:45:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850704": [
        {
            "ioc_value": "192.169.7.60:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:18",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850705": [
        {
            "ioc_value": "192.169.7.60:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:18",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850703": [
        {
            "ioc_value": "191.101.130.245:5199",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:17",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850702": [
        {
            "ioc_value": "185.223.57.86:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:44:12",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850701": [
        {
            "ioc_value": "185.115.164.59:53353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:44:06",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850700": [
        {
            "ioc_value": "158.94.211.63:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 19:43:47",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850699": [
        {
            "ioc_value": "155.103.71.115:15608",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850698": [
        {
            "ioc_value": "151.145.34.33:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-14 19:43:39",
            "last_seen_utc": "2026-08-11 03:24:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850697": [
        {
            "ioc_value": "147.182.143.172:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-14 19:43:36",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850696": [
        {
            "ioc_value": "147.124.214.170:4056",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 19:43:35",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850695": [
        {
            "ioc_value": "103.83.86.48:1616",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850666": [
        {
            "ioc_value": "45.55.232.28:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 18:05:08",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1850217": [
        {
            "ioc_value": "96.9.231.213:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:47:18",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850216": [
        {
            "ioc_value": "47.109.181.81:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:46:38",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850215": [
        {
            "ioc_value": "35.78.107.61:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:46:14",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850214": [
        {
            "ioc_value": "216.9.225.38:14649",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:45:59",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850213": [
        {
            "ioc_value": "204.44.69.214:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:51",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850212": [
        {
            "ioc_value": "20.226.72.17:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:44:48",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850211": [
        {
            "ioc_value": "198.135.49.85:62025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 09:44:41",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850210": [
        {
            "ioc_value": "192.255.195.147:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:34",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850209": [
        {
            "ioc_value": "185.115.164.60:65531",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:21",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850208": [
        {
            "ioc_value": "185.115.164.60:11883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-14 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850207": [
        {
            "ioc_value": "172.232.122.241:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:44:05",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850206": [
        {
            "ioc_value": "164.90.202.48:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:44:01",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850205": [
        {
            "ioc_value": "139.199.87.99:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850204": [
        {
            "ioc_value": "130.49.214.23:59838",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-14 09:43:30",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1850203": [
        {
            "ioc_value": "118.89.121.171:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-14 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849979": [
        {
            "ioc_value": "85.8.149.156:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:45:28",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849978": [
        {
            "ioc_value": "5.175.218.71:5691",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:45:13",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849977": [
        {
            "ioc_value": "45.59.114.202:9090",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-13 19:45:03",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849976": [
        {
            "ioc_value": "37.235.54.142:53236",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-13 19:44:54",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849974": [
        {
            "ioc_value": "23.27.52.106:28736",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-13 19:44:48",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849973": [
        {
            "ioc_value": "212.180.120.35:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:44:18",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849972": [
        {
            "ioc_value": "204.44.69.214:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:44:13",
            "last_seen_utc": "2026-08-11 02:44:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849970": [
        {
            "ioc_value": "192.255.195.147:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:44:03",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849971": [
        {
            "ioc_value": "192.255.195.147:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:44:03",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849968": [
        {
            "ioc_value": "188.209.158.161:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:44:00",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849969": [
        {
            "ioc_value": "188.209.158.161:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 19:44:00",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849967": [
        {
            "ioc_value": "185.212.131.27:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-13 19:43:57",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849966": [
        {
            "ioc_value": "172.86.119.141:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-13 19:43:44",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849965": [
        {
            "ioc_value": "128.90.105.247:7998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-13 19:43:19",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849964": [
        {
            "ioc_value": "113.31.102.219:21935",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849963": [
        {
            "ioc_value": "103.83.87.107:4098",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 19:43:11",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849758": [
        {
            "ioc_value": "133.18.165.80:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 14:05:50",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/dc14aa1d739c79a92ae7342a7f6941aab24df1b03fedd0a99d9a57cd972d569d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849751": [
        {
            "ioc_value": "133.18.165.80:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 14:00:05",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849657": [
        {
            "ioc_value": "91.92.42.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-13 09:46:37",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849656": [
        {
            "ioc_value": "216.9.225.38:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 09:45:31",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849655": [
        {
            "ioc_value": "211.159.223.14:22005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-13 09:44:45",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849654": [
        {
            "ioc_value": "188.209.158.161:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 09:44:23",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849653": [
        {
            "ioc_value": "136.111.38.101:6932",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-13 09:43:27",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849604": [
        {
            "ioc_value": "103.214.146.46:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.aisuru",
            "malware_alias": null,
            "malware_printable": "Aisuru",
            "first_seen_utc": "2026-07-13 07:03:02",
            "last_seen_utc": "2026-08-11 03:15:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://github.com/deepfield/public-research/blob/main/aisuru/README.md",
            "tags": "airashi,aisuru,botnet,c2,ddos,mirai",
            "anonymous": 0,
            "reporter": "deepfield"
        }
    ],
    "1849096": [
        {
            "ioc_value": "85.206.168.238:23501",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:46:07",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849094": [
        {
            "ioc_value": "45.198.224.93:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 19:45:37",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849092": [
        {
            "ioc_value": "23.106.52.176:2489",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:45:18",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849093": [
        {
            "ioc_value": "23.106.52.176:3984",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:45:18",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849091": [
        {
            "ioc_value": "211.159.223.14:22003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:44:38",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849090": [
        {
            "ioc_value": "178.73.218.4:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:44:04",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849089": [
        {
            "ioc_value": "157.20.182.18:1665",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:43:47",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849088": [
        {
            "ioc_value": "137.220.152.132:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:43:29",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849087": [
        {
            "ioc_value": "137.220.152.131:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 19:43:28",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849086": [
        {
            "ioc_value": "104.164.46.55:62721",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-12 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849071": [
        {
            "ioc_value": "103.11.41.19:52811",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:43:09",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1849072": [
        {
            "ioc_value": "103.11.41.19:64045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 19:43:09",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848961": [
        {
            "ioc_value": "196.251.121.120:35630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 11:05:05",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1848949": [
        {
            "ioc_value": "93.95.226.207:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-12 09:46:09",
            "last_seen_utc": "2026-08-11 02:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848946": [
        {
            "ioc_value": "45.61.149.187:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-12 09:45:32",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848947": [
        {
            "ioc_value": "45.61.149.187:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-12 09:45:32",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848948": [
        {
            "ioc_value": "45.61.149.187:8005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-12 09:45:32",
            "last_seen_utc": "2026-08-11 02:45:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848945": [
        {
            "ioc_value": "45.198.224.94:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:30",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848944": [
        {
            "ioc_value": "38.54.8.74:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:45:25",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848943": [
        {
            "ioc_value": "27.102.137.139:465",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 09:45:16",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848942": [
        {
            "ioc_value": "216.9.225.38:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-12 09:45:11",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848940": [
        {
            "ioc_value": "172.86.77.116:5656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-12 09:43:56",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848937": [
        {
            "ioc_value": "118.107.45.29:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848938": [
        {
            "ioc_value": "118.107.45.70:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848939": [
        {
            "ioc_value": "118.107.45.73:50555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-12 09:43:23",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848936": [
        {
            "ioc_value": "107.172.90.117:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-12 09:43:18",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848933": [
        {
            "ioc_value": "104.207.93.150:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-12 09:43:14",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848934": [
        {
            "ioc_value": "104.207.93.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-12 09:43:14",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848815": [
        {
            "ioc_value": "186.241.75.134:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 23:46:14",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848772": [
        {
            "ioc_value": "82.158.229.189:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848773": [
        {
            "ioc_value": "82.158.229.30:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:05",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848771": [
        {
            "ioc_value": "82.158.229.143:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:46:04",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848770": [
        {
            "ioc_value": "62.109.10.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-11 19:45:53",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848769": [
        {
            "ioc_value": "45.74.7.201:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-11 19:45:41",
            "last_seen_utc": "2026-08-11 02:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848768": [
        {
            "ioc_value": "31.207.4.197:9872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:45:23",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848767": [
        {
            "ioc_value": "23.106.52.176:59838",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 19:45:19",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848766": [
        {
            "ioc_value": "216.9.225.38:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-11 19:45:16",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848765": [
        {
            "ioc_value": "185.244.149.240:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-11 19:44:14",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848764": [
        {
            "ioc_value": "178.104.249.136:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:59",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848759": [
        {
            "ioc_value": "156.234.43.100:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848760": [
        {
            "ioc_value": "156.234.43.101:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848761": [
        {
            "ioc_value": "156.234.43.102:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848762": [
        {
            "ioc_value": "156.234.43.98:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848763": [
        {
            "ioc_value": "156.234.43.99:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:43",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848758": [
        {
            "ioc_value": "144.91.76.114:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-11 19:43:33",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848756": [
        {
            "ioc_value": "137.220.152.131:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:27",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848757": [
        {
            "ioc_value": "137.220.152.132:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 19:43:27",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848755": [
        {
            "ioc_value": "1.14.234.68:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-11 19:43:03",
            "last_seen_utc": "2026-08-11 02:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848617": [
        {
            "ioc_value": "139.155.157.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:39",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848616": [
        {
            "ioc_value": "123.58.64.57:50040",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:37",
            "last_seen_utc": "2026-08-11 02:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848615": [
        {
            "ioc_value": "115.190.237.175:6677",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 11:46:31",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848599": [
        {
            "ioc_value": "172.174.154.130:1024",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-11 11:05:05",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1848583": [
        {
            "ioc_value": "137.220.194.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 09:46:53",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848582": [
        {
            "ioc_value": "r0.erloro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 09:46:35",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848581": [
        {
            "ioc_value": "89.144.10.64:1604",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 09:46:21",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848580": [
        {
            "ioc_value": "69.10.49.136:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-11 09:46:08",
            "last_seen_utc": "2026-08-10 18:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848578": [
        {
            "ioc_value": "66.97.33.99:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-11 09:46:07",
            "last_seen_utc": "2026-08-10 18:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848579": [
        {
            "ioc_value": "67.211.221.131:65291",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-11 09:46:07",
            "last_seen_utc": "2026-08-10 18:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848575": [
        {
            "ioc_value": "103.195.238.98:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-11 09:43:11",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848544": [
        {
            "ioc_value": "81.70.21.248:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-11 08:52:51",
            "last_seen_utc": "2026-08-11 02:47:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848358": [
        {
            "ioc_value": "8.134.70.73:6111",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:33",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848357": [
        {
            "ioc_value": "137.220.194.15:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:08",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848356": [
        {
            "ioc_value": "115.190.237.175:23333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:46:00",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848355": [
        {
            "ioc_value": "112.124.106.45:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 23:45:58",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848289": [
        {
            "ioc_value": "93.115.172.235:7579",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-10 19:46:10",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848288": [
        {
            "ioc_value": "87.232.83.18:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-10 19:46:04",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848287": [
        {
            "ioc_value": "45.74.7.199:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:45:36",
            "last_seen_utc": "2026-08-11 02:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848286": [
        {
            "ioc_value": "45.74.7.191:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:45:35",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848285": [
        {
            "ioc_value": "216.133.157.16:21935",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:45:12",
            "last_seen_utc": "2026-08-10 08:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848284": [
        {
            "ioc_value": "155.103.71.115:13508",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:43:41",
            "last_seen_utc": "2026-08-09 18:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848283": [
        {
            "ioc_value": "144.31.117.38:47825",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-10 19:43:32",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848282": [
        {
            "ioc_value": "103.83.86.48:1818",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 19:43:13",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848062": [
        {
            "ioc_value": "bdm.kencangsm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-10 13:27:06",
            "last_seen_utc": "2026-08-11 03:24:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "mp44s1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1848061": [
        {
            "ioc_value": "https://bdm.kencangsm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-07-10 13:27:05",
            "last_seen_utc": "2026-08-11 03:24:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "mp44s1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847999": [
        {
            "ioc_value": "101.42.255.92:2234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 11:46:34",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847977": [
        {
            "ioc_value": "101.42.255.92:8081",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 10:05:08",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847971": [
        {
            "ioc_value": "85.206.168.238:26076",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:46:22",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847970": [
        {
            "ioc_value": "74.0.32.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:46:14",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847969": [
        {
            "ioc_value": "54.65.16.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-10 09:46:07",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847967": [
        {
            "ioc_value": "45.74.7.195:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:45:53",
            "last_seen_utc": "2026-08-11 02:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847966": [
        {
            "ioc_value": "38.207.176.218:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-10 09:45:41",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847965": [
        {
            "ioc_value": "207.180.250.181:10900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:44:41",
            "last_seen_utc": "2026-08-09 08:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847964": [
        {
            "ioc_value": "20.204.61.204:21891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:44:38",
            "last_seen_utc": "2026-08-09 18:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847963": [
        {
            "ioc_value": "179.43.149.253:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-10 09:44:08",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847962": [
        {
            "ioc_value": "155.103.69.30:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:43:45",
            "last_seen_utc": "2026-08-09 08:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847961": [
        {
            "ioc_value": "147.124.218.54:62025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:43:38",
            "last_seen_utc": "2026-08-09 18:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847960": [
        {
            "ioc_value": "13.73.107.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-10 09:43:27",
            "last_seen_utc": "2026-08-09 18:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847959": [
        {
            "ioc_value": "104.250.161.126:2061",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-10 09:43:16",
            "last_seen_utc": "2026-08-09 18:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847957": [
        {
            "ioc_value": "103.212.187.217:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-10 09:43:13",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847958": [
        {
            "ioc_value": "103.212.187.217:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-10 09:43:13",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847956": [
        {
            "ioc_value": "103.146.231.107:7771",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-10 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847955": [
        {
            "ioc_value": "100.31.133.28:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-10 09:43:03",
            "last_seen_utc": "2026-08-11 02:43:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847905": [
        {
            "ioc_value": "119.45.160.160:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 06:05:05",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847878": [
        {
            "ioc_value": "38.54.61.225:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 03:46:14",
            "last_seen_utc": "2026-08-10 08:47:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847877": [
        {
            "ioc_value": "101.34.235.198:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 03:45:49",
            "last_seen_utc": "2026-08-09 08:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847868": [
        {
            "ioc_value": "158.178.230.77:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-10 03:10:21",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847818": [
        {
            "ioc_value": "78.17.212.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 23:46:10",
            "last_seen_utc": "2026-08-10 08:47:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847817": [
        {
            "ioc_value": "59.110.23.216:8181",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 23:46:08",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847753": [
        {
            "ioc_value": "37.72.172.58:4212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:45:23",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847752": [
        {
            "ioc_value": "216.9.225.38:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 19:45:12",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847751": [
        {
            "ioc_value": "213.209.159.91:22",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 19:44:37",
            "last_seen_utc": "2026-08-11 02:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847750": [
        {
            "ioc_value": "212.46.38.117:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 19:44:36",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847749": [
        {
            "ioc_value": "185.244.149.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-07-09 19:44:12",
            "last_seen_utc": "2026-08-09 08:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847748": [
        {
            "ioc_value": "179.43.149.251:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 19:43:58",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847747": [
        {
            "ioc_value": "156.244.11.247:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847746": [
        {
            "ioc_value": "155.103.71.115:13507",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 19:43:40",
            "last_seen_utc": "2026-08-10 18:43:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847745": [
        {
            "ioc_value": "13.70.174.70:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 19:43:24",
            "last_seen_utc": "2026-08-09 08:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847744": [
        {
            "ioc_value": "122.114.12.155:17891",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847743": [
        {
            "ioc_value": "115.42.60.122:7912",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 19:43:21",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847105": [
        {
            "ioc_value": "157.20.182.18:4442",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 14:05:07",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1847068": [
        {
            "ioc_value": "203.91.75.89:5006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 11:47:21",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847007": [
        {
            "ioc_value": "91.92.242.180:1880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:37",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847005": [
        {
            "ioc_value": "88.151.72.143:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:32",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847004": [
        {
            "ioc_value": "84.247.142.79:8877",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:28",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847002": [
        {
            "ioc_value": "68.183.36.161:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:46:19",
            "last_seen_utc": "2026-08-10 18:46:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847001": [
        {
            "ioc_value": "62.60.226.157:1664",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:46:14",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1847000": [
        {
            "ioc_value": "5.230.201.242:1995",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:46:09",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846998": [
        {
            "ioc_value": "45.74.7.194:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:58",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846999": [
        {
            "ioc_value": "45.74.7.196:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:58",
            "last_seen_utc": "2026-08-11 02:46:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846997": [
        {
            "ioc_value": "45.150.36.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-09 09:45:52",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846996": [
        {
            "ioc_value": "38.60.125.143:12599",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:45:48",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846995": [
        {
            "ioc_value": "37.72.172.58:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:45:45",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846992": [
        {
            "ioc_value": "31.57.216.62:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:41",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846993": [
        {
            "ioc_value": "31.57.216.62:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:41",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846994": [
        {
            "ioc_value": "31.57.216.62:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:41",
            "last_seen_utc": "2026-08-10 18:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846991": [
        {
            "ioc_value": "216.9.225.38:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:45:33",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846990": [
        {
            "ioc_value": "202.1.31.83:2234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-09 09:44:39",
            "last_seen_utc": "2026-08-09 18:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846989": [
        {
            "ioc_value": "186.169.89.64:5471",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-09 09:44:21",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846988": [
        {
            "ioc_value": "179.43.149.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 09:44:06",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846987": [
        {
            "ioc_value": "179.43.149.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 09:44:05",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846986": [
        {
            "ioc_value": "178.16.53.193:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:44:04",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846984": [
        {
            "ioc_value": "176.120.22.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-07-09 09:44:00",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846983": [
        {
            "ioc_value": "173.249.22.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:59",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846982": [
        {
            "ioc_value": "172.94.44.154:7775",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:43:58",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846979": [
        {
            "ioc_value": "157.20.182.17:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:43:46",
            "last_seen_utc": "2026-08-09 18:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846980": [
        {
            "ioc_value": "157.20.182.18:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-09 09:43:46",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846977": [
        {
            "ioc_value": "157.173.195.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:45",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846978": [
        {
            "ioc_value": "157.173.195.214:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-09 09:43:45",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846976": [
        {
            "ioc_value": "144.208.127.243:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-09 09:43:33",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846975": [
        {
            "ioc_value": "144.208.127.243:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-09 09:43:32",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846974": [
        {
            "ioc_value": "142.202.191.251:8624",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-09 09:43:30",
            "last_seen_utc": "2026-08-09 18:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846913": [
        {
            "ioc_value": "39.105.201.165:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 06:51:11",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846849": [
        {
            "ioc_value": "193.29.13.44:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-09 02:05:05",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1846829": [
        {
            "ioc_value": "159.75.152.237:6654",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-09 00:46:41",
            "last_seen_utc": "2026-08-10 08:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846741": [
        {
            "ioc_value": "89.32.41.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-08 19:45:51",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mirai",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846740": [
        {
            "ioc_value": "89.106.83.84:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:50",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846738": [
        {
            "ioc_value": "45.74.7.192:2428",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:24",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846739": [
        {
            "ioc_value": "45.74.7.193:4509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:24",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846737": [
        {
            "ioc_value": "216.9.225.38:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:45:00",
            "last_seen_utc": "2026-08-10 08:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846736": [
        {
            "ioc_value": "213.209.159.91:4556",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-08 19:44:32",
            "last_seen_utc": "2026-08-11 02:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846735": [
        {
            "ioc_value": "202.61.130.106:8321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 19:44:24",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846734": [
        {
            "ioc_value": "179.43.149.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 19:43:55",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846733": [
        {
            "ioc_value": "164.68.123.50:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 19:43:45",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846731": [
        {
            "ioc_value": "104.64.192.34:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-08 19:43:14",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846730": [
        {
            "ioc_value": "104.168.7.195:31897",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 19:43:13",
            "last_seen_utc": "2026-08-09 08:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846597": [
        {
            "ioc_value": "217.60.195.113:80",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-07-08 13:34:06",
            "last_seen_utc": "2026-08-10 12:48:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,honeypot",
            "anonymous": 0,
            "reporter": "nullblue67"
        }
    ],
    "1846504": [
        {
            "ioc_value": "185.92.190.185:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:49",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846505": [
        {
            "ioc_value": "185.92.190.187:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:49",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846503": [
        {
            "ioc_value": "173.249.27.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 11:46:47",
            "last_seen_utc": "2026-08-09 08:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846462": [
        {
            "ioc_value": "89.106.83.75:8015",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-08 09:46:12",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846458": [
        {
            "ioc_value": "202.61.130.170:8321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-08 09:44:32",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846454": [
        {
            "ioc_value": "162.248.102.130:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-08 09:43:47",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846419": [
        {
            "ioc_value": "139.226.191.149:2082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-08 07:40:42",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846237": [
        {
            "ioc_value": "185.92.190.183:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846238": [
        {
            "ioc_value": "185.92.190.184:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-08-11 02:47:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846239": [
        {
            "ioc_value": "185.92.190.186:8898",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-07 23:46:32",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846191": [
        {
            "ioc_value": "8.133.197.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-07 19:45:48",
            "last_seen_utc": "2026-08-10 18:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846190": [
        {
            "ioc_value": "62.192.173.164:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-07 19:45:41",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846182": [
        {
            "ioc_value": "172.93.144.150:8580",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-07 19:43:50",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846179": [
        {
            "ioc_value": "144.172.88.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-07 19:43:29",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846003": [
        {
            "ioc_value": "93.152.224.44:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-07 09:46:09",
            "last_seen_utc": "2026-08-11 02:46:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846002": [
        {
            "ioc_value": "91.92.33.250:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-07 09:46:08",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1846001": [
        {
            "ioc_value": "89.106.83.79:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:46:04",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845999": [
        {
            "ioc_value": "209.54.103.155:14646",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-07 09:44:33",
            "last_seen_utc": "2026-08-10 18:44:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845803": [
        {
            "ioc_value": "217.60.97.2:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-06 19:45:03",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845588": [
        {
            "ioc_value": "38.46.218.34:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2026-07-06 10:58:18",
            "last_seen_utc": "2026-08-11 00:18:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "loader,Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1845508": [
        {
            "ioc_value": "101.34.235.198:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-06 09:46:41",
            "last_seen_utc": "2026-08-09 08:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845507": [
        {
            "ioc_value": "82.23.248.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:46:17",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845505": [
        {
            "ioc_value": "23.95.217.96:6745",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-06 09:45:31",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845504": [
        {
            "ioc_value": "222.167.211.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:45:29",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845503": [
        {
            "ioc_value": "216.203.20.22:18190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:45:27",
            "last_seen_utc": "2026-08-11 02:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845502": [
        {
            "ioc_value": "203.161.57.75:8234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-06 09:44:36",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845501": [
        {
            "ioc_value": "2.56.212.64:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:44:34",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845499": [
        {
            "ioc_value": "2.27.122.16:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-07-06 09:44:33",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845498": [
        {
            "ioc_value": "2.137.3.71:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-07-06 09:44:31",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845497": [
        {
            "ioc_value": "173.249.41.141:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:59",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845496": [
        {
            "ioc_value": "157.245.54.75:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-06 09:43:45",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845493": [
        {
            "ioc_value": "143.198.120.167:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-06 09:43:32",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845348": [
        {
            "ioc_value": "35.239.131.165:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-06 05:05:04",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1845295": [
        {
            "ioc_value": "77.105.169.126:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-07-05 19:45:53",
            "last_seen_utc": "2026-08-11 02:46:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845294": [
        {
            "ioc_value": "31.220.93.222:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 19:45:18",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845293": [
        {
            "ioc_value": "194.26.192.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-05 19:44:18",
            "last_seen_utc": "2026-08-11 02:44:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845266": [
        {
            "ioc_value": "141.94.121.162:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 18:05:04",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1845011": [
        {
            "ioc_value": "111.229.248.198:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 13:33:27",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1845009": [
        {
            "ioc_value": "47.96.254.114:5555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 13:33:13",
            "last_seen_utc": "2026-08-10 06:28:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-305419896",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844990": [
        {
            "ioc_value": "141.255.162.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-05 11:46:59",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844960": [
        {
            "ioc_value": "http://91.202.233.134/4d95d68e3fc64f3bbbf5.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-07-05 09:50:45",
            "last_seen_utc": "2026-08-11 03:01:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/1095cf2951bbc8b1ecd33798afad192449a102aa1b976fb60bf566a08d693587/",
            "tags": "stealc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844953": [
        {
            "ioc_value": "170.168.15.43:4322",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 09:43:57",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844951": [
        {
            "ioc_value": "144.31.62.81:56123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-05 09:43:36",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844949": [
        {
            "ioc_value": "143.92.43.241:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844950": [
        {
            "ioc_value": "143.92.43.246:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844948": [
        {
            "ioc_value": "143.92.43.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-05 09:43:34",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844861": [
        {
            "ioc_value": "110.40.147.249:60010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 23:45:52",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844840": [
        {
            "ioc_value": "92.4.65.88:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-04 19:45:47",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844835": [
        {
            "ioc_value": "179.43.149.250:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-04 19:43:50",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844834": [
        {
            "ioc_value": "155.103.69.30:14642",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 19:43:33",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844655": [
        {
            "ioc_value": "103.42.30.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-04 15:05:05",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1844476": [
        {
            "ioc_value": "46.151.182.138:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-04 09:46:00",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844471": [
        {
            "ioc_value": "130.12.182.95:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 09:43:25",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844085": [
        {
            "ioc_value": "186.169.89.64:5010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 07:10:33",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRat,DDNS",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1844087": [
        {
            "ioc_value": "186.169.89.64:9140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-04 07:10:33",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AsyncRat,DDNS",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1844166": [
        {
            "ioc_value": "86.109.75.177:17635",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-03 19:46:03",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844165": [
        {
            "ioc_value": "46.246.6.3:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-03 19:45:39",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844164": [
        {
            "ioc_value": "37.244.255.240:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-03 19:45:22",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844163": [
        {
            "ioc_value": "212.193.23.223:8089",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.hook",
            "malware_alias": null,
            "malware_printable": "Hook",
            "first_seen_utc": "2026-07-03 19:44:34",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Hook",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844078": [
        {
            "ioc_value": "172.245.226.120:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-03 15:46:27",
            "last_seen_utc": "2026-08-09 08:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1844077": [
        {
            "ioc_value": "1.14.217.176:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-03 15:46:06",
            "last_seen_utc": "2026-08-09 08:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843961": [
        {
            "ioc_value": "94.156.179.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-03 09:46:03",
            "last_seen_utc": "2026-08-11 02:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843958": [
        {
            "ioc_value": "155.103.69.30:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843956": [
        {
            "ioc_value": "113.31.102.219:21915",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-03 09:43:18",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843816": [
        {
            "ioc_value": "106.13.78.105:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 23:45:57",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843762": [
        {
            "ioc_value": "177.22.119.174:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-07-02 19:43:58",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843760": [
        {
            "ioc_value": "172.94.18.103:70",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 19:43:55",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843757": [
        {
            "ioc_value": "155.103.69.30:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 19:43:39",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843754": [
        {
            "ioc_value": "143.92.43.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843755": [
        {
            "ioc_value": "143.92.43.241:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843756": [
        {
            "ioc_value": "143.92.43.246:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 19:43:31",
            "last_seen_utc": "2026-08-11 02:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843500": [
        {
            "ioc_value": "82.157.78.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 12:05:06",
            "last_seen_utc": "2026-08-11 02:47:27",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843418": [
        {
            "ioc_value": "220.154.3.197:9003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 11:44:21",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Mythic,MythicC2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1843426": [
        {
            "ioc_value": "167.99.166.159:8686",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 11:44:19",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Mythic,MythicC2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1843475": [
        {
            "ioc_value": "39.106.80.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 10:05:08",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843465": [
        {
            "ioc_value": "82.165.79.60:12001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843466": [
        {
            "ioc_value": "82.165.79.60:12002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-07-02 09:45:46",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843463": [
        {
            "ioc_value": "70.34.251.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-07-02 09:45:42",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843461": [
        {
            "ioc_value": "209.54.103.155:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-02 09:44:25",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843460": [
        {
            "ioc_value": "192.162.242.202:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-07-02 09:44:08",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843456": [
        {
            "ioc_value": "162.243.54.45:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-02 09:43:39",
            "last_seen_utc": "2026-08-10 08:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843455": [
        {
            "ioc_value": "159.65.42.43:60560",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-07-02 09:43:38",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843453": [
        {
            "ioc_value": "141.94.121.162:6060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-07-02 09:43:24",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843452": [
        {
            "ioc_value": "136.111.38.101:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-02 09:43:21",
            "last_seen_utc": "2026-08-11 02:43:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843432": [
        {
            "ioc_value": "121.43.181.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 08:15:52",
            "last_seen_utc": "2026-08-11 02:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843356": [
        {
            "ioc_value": "23.132.164.13:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-02 05:00:09",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "60223,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1843364": [
        {
            "ioc_value": "158.160.191.88:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-02 03:05:05",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "mythic",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1843350": [
        {
            "ioc_value": "209.200.246.194:37865",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 23:46:22",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843300": [
        {
            "ioc_value": "94.156.179.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 19:46:10",
            "last_seen_utc": "2026-08-11 02:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843298": [
        {
            "ioc_value": "62.4.0.66:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-01 19:45:50",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843296": [
        {
            "ioc_value": "209.54.103.155:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:44:35",
            "last_seen_utc": "2026-08-09 08:44:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843294": [
        {
            "ioc_value": "209.54.103.155:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-07-01 19:44:34",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843292": [
        {
            "ioc_value": "185.235.138.19:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 19:44:11",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1843290": [
        {
            "ioc_value": "181.225.233.172:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-07-01 19:43:58",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840781": [
        {
            "ioc_value": "http://midpfv.xyz:9549",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-07-01 13:55:43",
            "last_seen_utc": "2026-08-09 11:30:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/3eccd5e0b9da7735102c0e57c5c98668189c9ba964bf18508eabd9116aab6947/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840759": [
        {
            "ioc_value": "82.156.235.177:13321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 11:47:08",
            "last_seen_utc": "2026-08-11 02:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840745": [
        {
            "ioc_value": "195.242.118.161:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 09:44:17",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840741": [
        {
            "ioc_value": "137.184.216.236:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-07-01 09:43:24",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840740": [
        {
            "ioc_value": "130.12.182.95:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 09:43:22",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840739": [
        {
            "ioc_value": "109.237.64.48:44704",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-07-01 09:43:17",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840722": [
        {
            "ioc_value": "119.91.243.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 08:05:06",
            "last_seen_utc": "2026-08-11 02:47:01",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840704": [
        {
            "ioc_value": "43.144.19.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-07-01 07:05:06",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840396": [
        {
            "ioc_value": "63.250.57.91:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-07-01 05:50:04",
            "last_seen_utc": "2026-08-09 08:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "1472D1643B294C63AF66357816F6E5E66B427EBD,AsyncRAT,c2",
            "anonymous": 0,
            "reporter": "navneeet"
        }
    ],
    "1840432": [
        {
            "ioc_value": "107.173.42.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 23:45:49",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840431": [
        {
            "ioc_value": "cdn.soft-update.click",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 23:45:40",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840388": [
        {
            "ioc_value": "91.92.43.194:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840389": [
        {
            "ioc_value": "91.92.43.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840390": [
        {
            "ioc_value": "91.92.43.196:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:09",
            "last_seen_utc": "2026-08-11 02:46:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840387": [
        {
            "ioc_value": "91.92.43.193:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:08",
            "last_seen_utc": "2026-08-11 02:46:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840386": [
        {
            "ioc_value": "89.125.153.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:46:05",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840380": [
        {
            "ioc_value": "193.58.122.50:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 19:44:22",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840379": [
        {
            "ioc_value": "193.24.123.25:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:21",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840378": [
        {
            "ioc_value": "185.45.193.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:44:14",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840375": [
        {
            "ioc_value": "138.124.240.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840376": [
        {
            "ioc_value": "138.124.240.76:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840377": [
        {
            "ioc_value": "138.124.240.77:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.tsundere",
            "malware_alias": "DinDoor",
            "malware_printable": "Tsundere",
            "first_seen_utc": "2026-06-30 19:43:26",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DinDoor,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840372": [
        {
            "ioc_value": "107.172.22.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 19:43:15",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840357": [
        {
            "ioc_value": "89.110.90.71:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:45:50",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840353": [
        {
            "ioc_value": "45.74.7.172:1488",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:45:21",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840352": [
        {
            "ioc_value": "41.216.189.153:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-30 17:45:13",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840351": [
        {
            "ioc_value": "2.26.1.177:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-30 17:44:15",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840350": [
        {
            "ioc_value": "185.117.90.47:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-30 17:43:56",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840348": [
        {
            "ioc_value": "173.249.41.192:773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-30 17:43:47",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840347": [
        {
            "ioc_value": "172.94.18.103:69",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 17:43:45",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840271": [
        {
            "ioc_value": "152.32.132.177:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 09:54:11",
            "last_seen_utc": "2026-08-10 08:08:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840265": [
        {
            "ioc_value": "170.64.130.99:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:50",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840262": [
        {
            "ioc_value": "141.94.121.162:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-30 09:43:27",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840261": [
        {
            "ioc_value": "136.113.49.8:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-30 09:43:24",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840202": [
        {
            "ioc_value": "1.14.227.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": "2026-08-09 08:46:59",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840203": [
        {
            "ioc_value": "130.12.182.95:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-30 05:05:05",
            "last_seen_utc": "2026-08-11 02:43:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840153": [
        {
            "ioc_value": "81.90.31.253:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-29 19:45:30",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1840094": [
        {
            "ioc_value": "104.251.181.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-29 19:05:06",
            "last_seen_utc": "2026-08-11 02:43:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1840093": [
        {
            "ioc_value": "172.245.226.124:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 19:05:05",
            "last_seen_utc": "2026-08-09 08:47:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1839241": [
        {
            "ioc_value": "209.200.246.194:35885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:48",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839238": [
        {
            "ioc_value": "updatesrv.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839239": [
        {
            "ioc_value": "web-analyzer-serv32.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-29 11:46:18",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839220": [
        {
            "ioc_value": "45.92.158.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-29 09:45:31",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1839218": [
        {
            "ioc_value": "27.102.137.139:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-29 09:45:08",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838803": [
        {
            "ioc_value": "54.180.147.42:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-28 19:45:13",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838800": [
        {
            "ioc_value": "45.94.23.42:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-28 19:45:00",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838799": [
        {
            "ioc_value": "45.150.38.95:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-28 19:44:54",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838789": [
        {
            "ioc_value": "104.248.201.191:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-28 19:05:05",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838757": [
        {
            "ioc_value": "45.74.7.173:9521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:45:16",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838755": [
        {
            "ioc_value": "185.212.128.231:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-28 09:43:55",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838751": [
        {
            "ioc_value": "141.98.10.150:14648",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:21",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838750": [
        {
            "ioc_value": "103.83.87.87:25900",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-28 09:43:09",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838674": [
        {
            "ioc_value": "80.211.129.141:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:43",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838668": [
        {
            "ioc_value": "45.74.7.170:3305",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:22",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838666": [
        {
            "ioc_value": "45.74.7.165:8455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:21",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838667": [
        {
            "ioc_value": "45.74.7.169:7312",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-27 19:45:21",
            "last_seen_utc": "2026-08-11 02:46:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838665": [
        {
            "ioc_value": "45.141.234.47:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:45:17",
            "last_seen_utc": "2026-08-11 02:45:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838663": [
        {
            "ioc_value": "185.212.128.139:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-27 19:43:58",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838660": [
        {
            "ioc_value": "155.94.163.75:8797",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 19:43:32",
            "last_seen_utc": "2026-08-11 02:43:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838659": [
        {
            "ioc_value": "138.124.84.7:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-27 19:43:20",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838656": [
        {
            "ioc_value": "107.173.160.177:2850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-27 19:43:12",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838629": [
        {
            "ioc_value": "47.86.184.71:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:40",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838628": [
        {
            "ioc_value": "test.officeplustool.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 15:46:01",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838555": [
        {
            "ioc_value": "188.212.158.4:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-27 08:05:05",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838532": [
        {
            "ioc_value": "8.152.212.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 07:05:05",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838478": [
        {
            "ioc_value": "47.108.60.27:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-27 06:24:31",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "37963,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1838492": [
        {
            "ioc_value": "20.69.167.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-27 03:05:08",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1838183": [
        {
            "ioc_value": "82.165.79.60:1336",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-26 19:45:25",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838123": [
        {
            "ioc_value": "https://k1h.hopesm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-08-11 03:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1838124": [
        {
            "ioc_value": "k1h.hopesm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-26 12:25:15",
            "last_seen_utc": "2026-08-11 03:23:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "k5yss1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837880": [
        {
            "ioc_value": "122.51.221.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-26 07:18:38",
            "last_seen_utc": "2026-08-11 02:47:02",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1837848": [
        {
            "ioc_value": "49.232.4.71:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 21:05:09",
            "last_seen_utc": "2026-08-09 08:47:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1837840": [
        {
            "ioc_value": "217.60.97.3:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-25 19:45:00",
            "last_seen_utc": "2026-08-11 02:45:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837476": [
        {
            "ioc_value": "45.192.211.64:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837477": [
        {
            "ioc_value": "45.192.211.64:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837478": [
        {
            "ioc_value": "45.192.211.64:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:54:02",
            "last_seen_utc": "2026-08-11 02:45:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837499": [
        {
            "ioc_value": "216.107.139.88:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 18:53:44",
            "last_seen_utc": "2026-08-11 02:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837441": [
        {
            "ioc_value": "45.192.211.59:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:46",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837442": [
        {
            "ioc_value": "45.192.211.59:56002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:45",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837443": [
        {
            "ioc_value": "45.192.211.59:56003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 15:17:44",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,ResolverRAT",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1837293": [
        {
            "ioc_value": "45.74.7.166:1377",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-25 09:45:43",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837286": [
        {
            "ioc_value": "104.250.167.40:9093",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-25 09:43:11",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837265": [
        {
            "ioc_value": "45.192.211.63:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-25 08:21:13",
            "last_seen_utc": "2026-08-11 02:45:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837243": [
        {
            "ioc_value": "169.239.128.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-25 08:08:03",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837088": [
        {
            "ioc_value": "45.74.7.163:6448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:18",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837089": [
        {
            "ioc_value": "45.74.7.164:6913",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:18",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837087": [
        {
            "ioc_value": "45.74.7.155:1202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 19:45:17",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1837080": [
        {
            "ioc_value": "146.190.80.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-24 19:43:22",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836784": [
        {
            "ioc_value": "95.81.79.153:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:45:56",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836783": [
        {
            "ioc_value": "45.74.7.160:9405",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:45:24",
            "last_seen_utc": "2026-08-11 02:46:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836775": [
        {
            "ioc_value": "154.219.98.36:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-24 09:43:30",
            "last_seen_utc": "2026-08-10 08:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836776": [
        {
            "ioc_value": "154.219.98.36:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-06-24 09:43:30",
            "last_seen_utc": "2026-08-10 08:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836774": [
        {
            "ioc_value": "141.98.10.150:14647",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-24 09:43:23",
            "last_seen_utc": "2026-08-10 08:43:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836771": [
        {
            "ioc_value": "107.172.140.187:32333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-24 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836745": [
        {
            "ioc_value": "45.192.211.77:56001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pure_rat",
            "malware_alias": "PureHVNC,ResolverRAT",
            "malware_printable": "PureRAT",
            "first_seen_utc": "2026-06-24 07:46:37",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/d025a29613e300d7755f878eb1d23d8a8a042cb2d3eb9005d66664ab9b97c677/",
            "tags": "PureHVNC,PureRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836703": [
        {
            "ioc_value": "www.rmsmarineservice.com.qwqqwq.ggff.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-24 03:45:54",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836665": [
        {
            "ioc_value": "188.23.173.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-23 19:44:02",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836662": [
        {
            "ioc_value": "156.239.47.147:4221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-23 19:43:29",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836278": [
        {
            "ioc_value": "111.231.173.74:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-23 07:14:51",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1836201": [
        {
            "ioc_value": "62.234.22.228:51123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 23:46:20",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835573": [
        {
            "ioc_value": "204.194.54.198:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:46:29",
            "last_seen_utc": "2026-08-09 08:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835572": [
        {
            "ioc_value": "ns2.msgkg.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:46:01",
            "last_seen_utc": "2026-08-09 08:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835571": [
        {
            "ioc_value": "ns1.msgkg.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-22 09:45:59",
            "last_seen_utc": "2026-08-09 08:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835561": [
        {
            "ioc_value": "185.212.128.215:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-22 09:43:56",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835556": [
        {
            "ioc_value": "102.220.160.250:7829",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 09:43:03",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1835399": [
        {
            "ioc_value": "thisisafalsepositive.st",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-22 07:21:35",
            "last_seen_utc": "2026-08-11 03:08:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/54a62444672de4d11e9a3ebd67289f1afc4401d7f7631ac02e404c7d0ca257ca/",
            "tags": "c2,SilentNet",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1835400": [
        {
            "ioc_value": "216.250.250.247:4521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-22 07:05:53",
            "last_seen_utc": "2026-08-11 02:45:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8c63a57313ad2479a758ca018134377043acbeade2b457f7f3392364b78a4a32/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834771": [
        {
            "ioc_value": "89.42.134.220:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-21 09:45:40",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834770": [
        {
            "ioc_value": "51.79.51.255:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-21 09:45:23",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834540": [
        {
            "ioc_value": "102.220.160.217:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-20 19:43:02",
            "last_seen_utc": "2026-08-09 18:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834279": [
        {
            "ioc_value": "5.188.61.49:44443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-20 09:45:43",
            "last_seen_utc": "2026-08-11 02:46:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834277": [
        {
            "ioc_value": "45.32.64.12:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-20 09:45:31",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834275": [
        {
            "ioc_value": "217.60.195.176:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-20 09:45:10",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834187": [
        {
            "ioc_value": "23.141.12.111:8899",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 23:46:13",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834170": [
        {
            "ioc_value": "97.74.92.237:63334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 19:45:40",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834168": [
        {
            "ioc_value": "211.235.43.192:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:17",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834167": [
        {
            "ioc_value": "205.209.106.158:5228",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 19:44:13",
            "last_seen_utc": "2026-08-11 02:44:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834132": [
        {
            "ioc_value": "47.242.0.207:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834133": [
        {
            "ioc_value": "47.242.0.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:46:26",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834131": [
        {
            "ioc_value": "114.134.187.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 15:45:55",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834098": [
        {
            "ioc_value": "185.92.190.214:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834099": [
        {
            "ioc_value": "185.92.190.216:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-19 11:46:35",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834063": [
        {
            "ioc_value": "77.110.119.172:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 09:45:43",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834053": [
        {
            "ioc_value": "138.2.120.11:61234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-19 09:43:18",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834051": [
        {
            "ioc_value": "103.153.254.32:6933",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-19 09:43:05",
            "last_seen_utc": "2026-08-11 02:43:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1834050": [
        {
            "ioc_value": "102.220.160.217:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-19 09:43:03",
            "last_seen_utc": "2026-08-09 18:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833837": [
        {
            "ioc_value": "165.227.123.79:6504",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.iclickfix",
            "malware_alias": null,
            "malware_printable": "IClickFix",
            "first_seen_utc": "2026-06-19 05:57:11",
            "last_seen_utc": "2026-08-11 03:12:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AddType,ClickFix,DigitalOcean,FakeCAPTCHA,mtls,nginx,one-check.lol,PowerShell,TLS1.3",
            "anonymous": 0,
            "reporter": "init_0"
        }
    ],
    "1833854": [
        {
            "ioc_value": "141.98.10.150:14643",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833855": [
        {
            "ioc_value": "141.98.10.150:14644",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-08-09 08:43:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833856": [
        {
            "ioc_value": "141.98.10.150:14645",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-18 19:43:17",
            "last_seen_utc": "2026-08-11 02:43:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833852": [
        {
            "ioc_value": "115.190.108.6:54233",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-06-18 19:43:11",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833848": [
        {
            "ioc_value": "102.220.160.217:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-18 19:43:03",
            "last_seen_utc": "2026-08-09 18:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833744": [
        {
            "ioc_value": "209.99.191.33:440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-18 09:44:25",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833622": [
        {
            "ioc_value": "106.13.189.138:56000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 23:45:31",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833598": [
        {
            "ioc_value": "185.212.128.176:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-17 19:43:49",
            "last_seen_utc": "2026-08-11 02:44:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833593": [
        {
            "ioc_value": "103.110.80.154:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-17 19:43:04",
            "last_seen_utc": "2026-08-10 08:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833500": [
        {
            "ioc_value": "20.39.60.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-17 17:00:15",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833440": [
        {
            "ioc_value": "147.93.191.75:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-17 12:00:22",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1833435": [
        {
            "ioc_value": "185.92.190.217:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-17 11:46:36",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833392": [
        {
            "ioc_value": "103.53.80.201:1235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-17 09:43:10",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833008": [
        {
            "ioc_value": "212.14.244.222:807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1833009": [
        {
            "ioc_value": "212.14.244.222:809",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 23:46:00",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832762": [
        {
            "ioc_value": "119.59.118.75:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 19:43:12",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832647": [
        {
            "ioc_value": "39.106.205.6:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-16 11:00:15",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832633": [
        {
            "ioc_value": "91.132.161.21:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:45:48",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832629": [
        {
            "ioc_value": "2.26.229.254:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:44:09",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832615": [
        {
            "ioc_value": "136.111.38.101:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:15",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832616": [
        {
            "ioc_value": "136.111.38.101:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-16 09:43:15",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832612": [
        {
            "ioc_value": "118.107.5.209:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-16 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832399": [
        {
            "ioc_value": "23.95.170.223:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:46:19",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832398": [
        {
            "ioc_value": "cs.tpedu2metricstw.dpdns.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 15:45:49",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832378": [
        {
            "ioc_value": "79.175.189.207:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-15 14:00:16",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1832323": [
        {
            "ioc_value": "89.42.134.220:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-15 09:45:54",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832320": [
        {
            "ioc_value": "8.210.84.56:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:45:46",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832317": [
        {
            "ioc_value": "213.193.20.192:9281",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:44:22",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832313": [
        {
            "ioc_value": "131.143.251.246:53921",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-15 09:43:17",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832163": [
        {
            "ioc_value": "89.42.134.220:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-14 19:45:30",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832158": [
        {
            "ioc_value": "43.133.164.200:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 19:44:54",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832074": [
        {
            "ioc_value": "23.254.129.251:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:50",
            "last_seen_utc": "2026-08-10 08:47:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1832072": [
        {
            "ioc_value": "sys.systemworld.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 11:45:27",
            "last_seen_utc": "2026-08-10 08:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831995": [
        {
            "ioc_value": "64.225.102.218:31400",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-14 09:45:07",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831992": [
        {
            "ioc_value": "23.235.185.42:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-14 09:44:35",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831987": [
        {
            "ioc_value": "185.207.154.11:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-14 09:43:43",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831979": [
        {
            "ioc_value": "49.232.4.71:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-14 09:00:14",
            "last_seen_utc": "2026-08-09 08:47:30",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1831842": [
        {
            "ioc_value": "85.121.176.239:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-13 19:45:34",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831732": [
        {
            "ioc_value": "89.42.134.220:1991",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-13 09:46:08",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831727": [
        {
            "ioc_value": "23.235.185.44:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-13 09:45:15",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831725": [
        {
            "ioc_value": "185.212.129.185:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-13 09:44:06",
            "last_seen_utc": "2026-08-10 08:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831722": [
        {
            "ioc_value": "130.185.82.117:5641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:18",
            "last_seen_utc": "2026-08-11 02:43:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831720": [
        {
            "ioc_value": "108.181.115.254:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831721": [
        {
            "ioc_value": "108.181.115.254:7045",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-06-13 09:43:12",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1831717": [
        {
            "ioc_value": "101.33.202.134:9989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-13 09:43:02",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830851": [
        {
            "ioc_value": "78.141.208.70:46337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:45:24",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830849": [
        {
            "ioc_value": "64.89.162.178:5903",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-12 09:45:21",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830843": [
        {
            "ioc_value": "31.57.184.154:7008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-12 09:44:45",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830834": [
        {
            "ioc_value": "114.132.238.70:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:11",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830833": [
        {
            "ioc_value": "110.42.34.220:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-12 09:43:10",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830416": [
        {
            "ioc_value": "49.233.136.227:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 21:00:15",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1830392": [
        {
            "ioc_value": "23.235.185.45:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:35",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830393": [
        {
            "ioc_value": "23.235.185.46:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-11 19:44:35",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830390": [
        {
            "ioc_value": "209.99.188.193:43221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:44:02",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830387": [
        {
            "ioc_value": "192.3.139.18:15221",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 19:43:50",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830291": [
        {
            "ioc_value": "159.89.48.54:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-11 12:46:30",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/159.89.48.54#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1830206": [
        {
            "ioc_value": "117.72.159.215:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 12:42:24",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.159.215#8080",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1830053": [
        {
            "ioc_value": "206.81.21.156:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-11 09:44:07",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830007": [
        {
            "ioc_value": "45.87.53.6:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:05",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830006": [
        {
            "ioc_value": "120.55.3.157:10000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:43:04",
            "last_seen_utc": "2026-08-11 02:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830004": [
        {
            "ioc_value": "43.136.180.88:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:48",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830002": [
        {
            "ioc_value": "43.136.180.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830003": [
        {
            "ioc_value": "47.121.181.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:47",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1830001": [
        {
            "ioc_value": "124.220.41.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 06:42:46",
            "last_seen_utc": "2026-08-11 02:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829957": [
        {
            "ioc_value": "192.144.213.21:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-11 05:26:05",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "45090,c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1829907": [
        {
            "ioc_value": "64.89.162.178:5902",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-10 19:45:10",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829903": [
        {
            "ioc_value": "23.235.185.43:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-10 19:44:35",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829902": [
        {
            "ioc_value": "216.158.235.73:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:44:33",
            "last_seen_utc": "2026-08-11 02:45:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829899": [
        {
            "ioc_value": "193.135.137.240:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-10 19:43:51",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829893": [
        {
            "ioc_value": "172.94.18.103:71",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-10 19:43:34",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829892": [
        {
            "ioc_value": "170.39.185.141:2030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 19:43:32",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829779": [
        {
            "ioc_value": "185.92.190.214:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829780": [
        {
            "ioc_value": "185.92.190.215:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829781": [
        {
            "ioc_value": "185.92.190.215:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829782": [
        {
            "ioc_value": "185.92.190.216:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829783": [
        {
            "ioc_value": "185.92.190.217:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:53",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829777": [
        {
            "ioc_value": "185.92.190.213:5896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1829778": [
        {
            "ioc_value": "185.92.190.213:8896",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 11:45:52",
            "last_seen_utc": "2026-08-11 02:47:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825867": [
        {
            "ioc_value": "64.89.162.117:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-10 09:45:40",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825853": [
        {
            "ioc_value": "192.208.12.91:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:44:00",
            "last_seen_utc": "2026-08-11 02:44:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825850": [
        {
            "ioc_value": "163.245.217.48:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-06-10 09:43:35",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825788": [
        {
            "ioc_value": "34.92.128.98:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 07:18:53",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825759": [
        {
            "ioc_value": "195.222.53.130:5200",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remus",
            "malware_alias": null,
            "malware_printable": "Remus",
            "first_seen_utc": "2026-06-10 06:44:39",
            "last_seen_utc": "2026-08-11 01:24:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/438ddb05451660c60d9843e3a32faca34a448071c716083c96cc97c781878563/",
            "tags": "remus",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825703": [
        {
            "ioc_value": "8.163.59.20:8008",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 06:00:25",
            "last_seen_utc": "2026-08-11 02:47:26",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825678": [
        {
            "ioc_value": "218.244.142.4:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-10 03:45:38",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825631": [
        {
            "ioc_value": "198.46.199.110:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 21:45:51",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825614": [
        {
            "ioc_value": "45.87.53.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-09 20:00:17",
            "last_seen_utc": "2026-08-10 08:08:25",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1825613": [
        {
            "ioc_value": "46.151.182.16:1011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-09 19:44:51",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1825226": [
        {
            "ioc_value": "155.103.70.100:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 19:43:23",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824909": [
        {
            "ioc_value": "155.103.70.100:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-08 09:43:22",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824508": [
        {
            "ioc_value": "209.200.246.194:17568",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-07 23:45:14",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824433": [
        {
            "ioc_value": "82.156.224.184:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:45:00",
            "last_seen_utc": "2026-08-11 02:46:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824430": [
        {
            "ioc_value": "45.38.20.122:8989",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 19:44:40",
            "last_seen_utc": "2026-08-09 08:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824426": [
        {
            "ioc_value": "172.189.57.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-07 19:43:30",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824259": [
        {
            "ioc_value": "60.191.87.107:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-06-07 09:45:24",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824255": [
        {
            "ioc_value": "31.57.184.154:2505",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-07 09:44:50",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824254": [
        {
            "ioc_value": "209.99.188.193:4323",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:44:10",
            "last_seen_utc": "2026-08-11 02:44:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824251": [
        {
            "ioc_value": "154.94.232.165:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-07 09:43:26",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824247": [
        {
            "ioc_value": "137.184.163.27:5613",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-07 09:43:16",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824130": [
        {
            "ioc_value": "46.151.182.243:55380",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-06 19:44:30",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824029": [
        {
            "ioc_value": "154.12.86.154:55555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824030": [
        {
            "ioc_value": "154.12.86.154:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824031": [
        {
            "ioc_value": "154.12.86.154:9004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 11:45:14",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1824012": [
        {
            "ioc_value": "47.101.51.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-06 10:32:30",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823853": [
        {
            "ioc_value": "https://pas.sm188star.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1823854": [
        {
            "ioc_value": "pas.sm188star.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-06-06 05:24:31",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ar3k0,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822764": [
        {
            "ioc_value": "158.247.194.144:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-05 09:43:29",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822600": [
        {
            "ioc_value": "34.202.161.96:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:28",
            "last_seen_utc": "2026-08-11 02:47:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822599": [
        {
            "ioc_value": "updates.fisgloval.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 23:45:07",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822526": [
        {
            "ioc_value": "163.172.174.237:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822527": [
        {
            "ioc_value": "163.172.174.237:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2026-06-04 19:43:27",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "BruteRatel,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822415": [
        {
            "ioc_value": "120.26.208.96:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 14:50:35",
            "last_seen_utc": "2026-08-11 02:47:01",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1822346": [
        {
            "ioc_value": "154.12.86.154:44444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-04 11:46:46",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822301": [
        {
            "ioc_value": "82.23.246.160:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:45:35",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822296": [
        {
            "ioc_value": "156.247.40.190:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-04 09:43:29",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822295": [
        {
            "ioc_value": "155.103.70.198:13408",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-04 09:43:28",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1822011": [
        {
            "ioc_value": "168.144.36.228:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 19:43:33",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821798": [
        {
            "ioc_value": "13.236.153.60:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-06-03 15:24:07",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821844": [
        {
            "ioc_value": "47.82.234.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-03 15:23:52",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1821877": [
        {
            "ioc_value": "4.240.85.243:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-03 14:36:55",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/4.240.85.243#7443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821716": [
        {
            "ioc_value": "82.23.246.160:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:45:37",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821713": [
        {
            "ioc_value": "156.247.40.190:12159",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-03 09:43:30",
            "last_seen_utc": "2026-08-11 02:43:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821517": [
        {
            "ioc_value": "45.198.224.19:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 19:45:08",
            "last_seen_utc": "2026-08-11 02:45:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821514": [
        {
            "ioc_value": "155.103.70.198:13407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-06-02 19:43:27",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1821233": [
        {
            "ioc_value": "172.236.10.250:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-06-02 14:06:11",
            "last_seen_utc": "2026-08-10 18:44:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/172.236.10.250#443",
            "tags": "c2,havoc,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821227": [
        {
            "ioc_value": "198.13.51.245:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-06-02 14:05:08",
            "last_seen_utc": "2026-08-11 02:44:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/198.13.51.245#4321",
            "tags": "adaptixc2,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1821221": [
        {
            "ioc_value": "34.61.52.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-06-02 14:04:12",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/34.61.52.162#443",
            "tags": "c2,mythic,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1820727": [
        {
            "ioc_value": "23.235.185.46:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:16",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820729": [
        {
            "ioc_value": "23.235.185.43:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:15",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820730": [
        {
            "ioc_value": "23.235.185.42:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-06-01 20:49:15",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820723": [
        {
            "ioc_value": "178.16.54.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:43",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820722": [
        {
            "ioc_value": "178.16.52.47:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-06-01 19:43:42",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820506": [
        {
            "ioc_value": "165.22.225.218:5443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-06-01 06:44:52",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820398": [
        {
            "ioc_value": "154.38.114.115:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:46:19",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820397": [
        {
            "ioc_value": "ds.metric-take-datadqct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-31 21:45:54",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820327": [
        {
            "ioc_value": "64.89.160.44:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-31 15:04:22",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1820291": [
        {
            "ioc_value": "64.176.73.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-31 09:45:39",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820290": [
        {
            "ioc_value": "31.57.184.154:2503",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 09:44:59",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820214": [
        {
            "ioc_value": "64.89.160.44:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-31 06:48:28",
            "last_seen_utc": "2026-08-11 02:46:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "205759,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1820025": [
        {
            "ioc_value": "45.153.34.212:8181",
            "ioc_type": "ip:port",
            "threat_type": "payload_delivery",
            "malware": "elf.mirai",
            "malware_alias": "Katana",
            "malware_printable": "Mirai",
            "first_seen_utc": "2026-05-30 15:14:02",
            "last_seen_utc": "2026-08-10 12:48:10",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": "https://twitter.com/NullBlue67",
            "tags": "docker-api,dropper,elf,Mirai",
            "anonymous": 0,
            "reporter": "nullblue67"
        }
    ],
    "1820043": [
        {
            "ioc_value": "38.54.63.135:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:45:23",
            "last_seen_utc": "2026-08-11 02:45:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1820039": [
        {
            "ioc_value": "114.132.190.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-30 09:43:14",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819982": [
        {
            "ioc_value": "40.85.252.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-30 07:04:38",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1819907": [
        {
            "ioc_value": "49.233.81.84:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:45:46",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819906": [
        {
            "ioc_value": "43.140.219.30:7112",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-29 19:45:33",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819904": [
        {
            "ioc_value": "27.102.137.139:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-29 19:45:20",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819903": [
        {
            "ioc_value": "23.235.185.44:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-29 19:45:19",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819901": [
        {
            "ioc_value": "192.162.199.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-29 19:44:12",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819895": [
        {
            "ioc_value": "162.248.224.236:7492",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819896": [
        {
            "ioc_value": "162.248.225.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819897": [
        {
            "ioc_value": "162.248.225.165:8603",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:42",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819894": [
        {
            "ioc_value": "162.248.224.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-29 19:43:41",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819893": [
        {
            "ioc_value": "157.20.182.17:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-29 19:43:36",
            "last_seen_utc": "2026-08-11 02:43:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819866": [
        {
            "ioc_value": "124.220.235.4:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 15:46:36",
            "last_seen_utc": "2026-08-11 02:47:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819842": [
        {
            "ioc_value": "mub.depansm188.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1819843": [
        {
            "ioc_value": "https://mub.depansm188.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-29 15:30:50",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1819786": [
        {
            "ioc_value": "118.89.79.131:6528",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-29 11:46:33",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819753": [
        {
            "ioc_value": "168.144.36.228:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-29 09:43:47",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819593": [
        {
            "ioc_value": "31.57.184.154:7005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:44:44",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819587": [
        {
            "ioc_value": "157.20.182.18:1444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-28 19:43:28",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819586": [
        {
            "ioc_value": "13.209.95.4:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 19:43:13",
            "last_seen_utc": "2026-08-11 02:43:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819406": [
        {
            "ioc_value": "91.215.85.212:45423",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:09",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819405": [
        {
            "ioc_value": "85.209.90.132:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:46:05",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819402": [
        {
            "ioc_value": "43.133.165.151:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:23",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819401": [
        {
            "ioc_value": "27.102.138.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:45:10",
            "last_seen_utc": "2026-08-10 18:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819396": [
        {
            "ioc_value": "202.95.8.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819397": [
        {
            "ioc_value": "202.95.8.98:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-28 09:44:19",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819394": [
        {
            "ioc_value": "193.5.65.169:4348",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819395": [
        {
            "ioc_value": "193.5.65.169:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-28 09:44:10",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819387": [
        {
            "ioc_value": "113.31.106.85:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-28 09:43:13",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819225": [
        {
            "ioc_value": "91.200.84.198:8515",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:55",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819224": [
        {
            "ioc_value": "45.32.236.190:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-27 19:45:18",
            "last_seen_utc": "2026-08-11 02:45:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819222": [
        {
            "ioc_value": "43.106.14.139:8085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-27 19:45:12",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819220": [
        {
            "ioc_value": "18.162.155.202:3350",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-27 19:43:47",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819218": [
        {
            "ioc_value": "104.243.248.63:1807",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-27 19:43:09",
            "last_seen_utc": "2026-08-10 08:43:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1819146": [
        {
            "ioc_value": "8.134.70.73:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 15:46:43",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818956": [
        {
            "ioc_value": "8.163.49.50:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-27 07:09:22",
            "last_seen_utc": "2026-08-11 02:47:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1818872": [
        {
            "ioc_value": "155.102.136.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-26 19:43:28",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818748": [
        {
            "ioc_value": "chekbrow.beer",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown_webinject",
            "malware_alias": null,
            "malware_printable": "Unknown Webinject",
            "first_seen_utc": "2026-05-26 11:29:33",
            "last_seen_utc": "2026-08-10 07:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ErrTraffic",
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1818696": [
        {
            "ioc_value": "193.24.123.160:45631",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-26 09:44:02",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818694": [
        {
            "ioc_value": "153.75.232.207:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-26 09:43:28",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818480": [
        {
            "ioc_value": "47.108.25.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 22:46:18",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818434": [
        {
            "ioc_value": "37.77.150.174:4333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:52",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818433": [
        {
            "ioc_value": "37.77.150.174:4332",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-05-25 19:44:51",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818432": [
        {
            "ioc_value": "27.102.137.139:1243",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-25 19:44:46",
            "last_seen_utc": "2026-08-11 02:45:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818431": [
        {
            "ioc_value": "202.95.8.92:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-25 19:44:05",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818426": [
        {
            "ioc_value": "157.20.182.17:1998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 19:43:27",
            "last_seen_utc": "2026-08-10 08:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818351": [
        {
            "ioc_value": "157.20.182.17:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-25 14:01:54",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1818346": [
        {
            "ioc_value": "45.153.127.224:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-25 14:00:07",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=45.153.127.224",
            "tags": "Chaos,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818253": [
        {
            "ioc_value": "134.175.78.181:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-25 06:57:09",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818107": [
        {
            "ioc_value": "31.171.131.118:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:45:21",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818104": [
        {
            "ioc_value": "157.20.182.18:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:36",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818103": [
        {
            "ioc_value": "157.20.182.17:9992",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 19:43:35",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818053": [
        {
            "ioc_value": "45.154.12.150:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:49",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818052": [
        {
            "ioc_value": "103.210.236.87:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:17",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818050": [
        {
            "ioc_value": "wsus.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1818051": [
        {
            "ioc_value": "wsus2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-24 14:46:12",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817829": [
        {
            "ioc_value": "172.94.18.103:75",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:05:15",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817873": [
        {
            "ioc_value": "172.94.18.103:73",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-24 11:04:56",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817758": [
        {
            "ioc_value": "https://cyy.turbo88ml.top/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:09",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817757": [
        {
            "ioc_value": "cyy.turbo88ml.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-23 22:00:08",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1817704": [
        {
            "ioc_value": "151.236.20.3:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-23 19:43:35",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817663": [
        {
            "ioc_value": "101.126.10.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:56",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817658": [
        {
            "ioc_value": "102.204.223.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:56:33",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817632": [
        {
            "ioc_value": "203.83.10.114:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-23 14:54:01",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1817427": [
        {
            "ioc_value": "88.119.167.142:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 19:45:35",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817206": [
        {
            "ioc_value": "46.20.109.225:8999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-22 11:36:04",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1817239": [
        {
            "ioc_value": "88.119.167.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-22 09:45:23",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817238": [
        {
            "ioc_value": "54.187.35.128:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:45:08",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817236": [
        {
            "ioc_value": "45.90.120.36:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 09:44:53",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817235": [
        {
            "ioc_value": "31.57.184.154:7006",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:40",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817233": [
        {
            "ioc_value": "31.171.131.118:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817234": [
        {
            "ioc_value": "31.171.131.118:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-22 09:44:39",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1817159": [
        {
            "ioc_value": "143.14.9.56:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-22 08:11:29",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": null,
            "tags": "adaptix_v1.2,adaptixc2,c2,panel",
            "anonymous": 0,
            "reporter": "Lenny_3BO"
        }
    ],
    "1817054": [
        {
            "ioc_value": "34.61.52.162:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-21 19:45:07",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816725": [
        {
            "ioc_value": "165.232.93.148:25001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.kimwolf",
            "malware_alias": null,
            "malware_printable": "Kimwolf",
            "first_seen_utc": "2026-05-21 05:00:06",
            "last_seen_utc": "2026-08-11 03:28:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Kimwolf",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1816738": [
        {
            "ioc_value": "41.216.189.163:43210",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:44:41",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816737": [
        {
            "ioc_value": "221.207.101.175:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-20 19:44:32",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816735": [
        {
            "ioc_value": "167.17.47.118:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 19:43:30",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816585": [
        {
            "ioc_value": "51.15.8.6:9998",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-20 09:45:05",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816583": [
        {
            "ioc_value": "202.1.31.83:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:56",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816581": [
        {
            "ioc_value": "178.212.13.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-20 09:43:39",
            "last_seen_utc": "2026-08-11 02:44:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816481": [
        {
            "ioc_value": "114.134.187.38:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-20 05:25:02",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1816445": [
        {
            "ioc_value": "43.142.137.169:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 20:46:09",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816431": [
        {
            "ioc_value": "91.202.233.214:44123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-19 19:45:18",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816427": [
        {
            "ioc_value": "31.57.184.154:2502",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 19:44:36",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816296": [
        {
            "ioc_value": "176.120.22.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-05-19 09:43:37",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PoshC2",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816294": [
        {
            "ioc_value": "142.93.165.129:3334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-19 09:43:19",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816172": [
        {
            "ioc_value": "47.82.234.12:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-19 05:16:15",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1816167": [
        {
            "ioc_value": "48.202.58.22:2055",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-19 05:16:08",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "8075,asyncrat,c2,censys",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1816106": [
        {
            "ioc_value": "89.125.255.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:45:01",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816100": [
        {
            "ioc_value": "38.147.189.199:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-18 19:44:31",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816096": [
        {
            "ioc_value": "138.124.90.26:51337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-18 19:43:13",
            "last_seen_utc": "2026-08-11 02:43:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1816037": [
        {
            "ioc_value": "207.180.250.181:10001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-18 18:05:44",
            "last_seen_utc": "2026-08-10 08:44:53",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "asyncrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815927": [
        {
            "ioc_value": "163.181.46.56:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-18 09:43:30",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815818": [
        {
            "ioc_value": "47.236.91.172:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-18 07:33:49",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "cobaltstrike",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815773": [
        {
            "ioc_value": "194.163.154.86:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-18 07:33:37",
            "last_seen_utc": "2026-08-10 08:44:37",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "havoc",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1815762": [
        {
            "ioc_value": "119.29.112.239:8005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-17 22:45:31",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815397": [
        {
            "ioc_value": "45.155.69.153:43345",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-16 19:45:35",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815137": [
        {
            "ioc_value": "95.231.168.143:4483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-15 19:44:50",
            "last_seen_utc": "2026-08-11 02:46:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815133": [
        {
            "ioc_value": "34.69.130.10:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-15 19:44:19",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1815073": [
        {
            "ioc_value": "pgo.fatherchrismas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-08-11 03:20:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1815074": [
        {
            "ioc_value": "https://pgo.fatherchrismas.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-15 16:00:12",
            "last_seen_utc": "2026-08-11 03:20:54",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1812280": [
        {
            "ioc_value": "104.243.248.63:1806",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-14 19:43:12",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1812073": [
        {
            "ioc_value": "87.120.107.68:7777",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-14 12:34:22",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "dcrat",
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "1812126": [
        {
            "ioc_value": "84.46.251.62:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-14 09:51:34",
            "last_seen_utc": "2026-08-11 02:46:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811945": [
        {
            "ioc_value": "43.230.162.44:14321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-13 19:44:54",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811412": [
        {
            "ioc_value": "117.72.168.103:50011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-12 11:45:38",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811399": [
        {
            "ioc_value": "85.158.57.247:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-12 09:45:14",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811385": [
        {
            "ioc_value": "104.243.248.63:1803",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-12 09:43:06",
            "last_seen_utc": "2026-08-11 02:43:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811187": [
        {
            "ioc_value": "mpd.pegasus-77.biz.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-08-11 03:20:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811188": [
        {
            "ioc_value": "https://mpd.pegasus-77.biz.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-11 23:00:12",
            "last_seen_utc": "2026-08-11 03:20:33",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1811186": [
        {
            "ioc_value": "117.50.184.221:10080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-11 22:45:16",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811129": [
        {
            "ioc_value": "64.199.252.59:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-11 19:45:07",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811128": [
        {
            "ioc_value": "51.77.54.76:6769",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:45:01",
            "last_seen_utc": "2026-08-11 02:46:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811126": [
        {
            "ioc_value": "45.77.89.29:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:44:49",
            "last_seen_utc": "2026-08-11 02:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1811118": [
        {
            "ioc_value": "109.73.193.242:10140",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 19:43:08",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810965": [
        {
            "ioc_value": "89.42.134.220:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:45:15",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810959": [
        {
            "ioc_value": "31.57.184.154:7007",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:44:29",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810958": [
        {
            "ioc_value": "20.114.142.61:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-11 09:43:46",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810955": [
        {
            "ioc_value": "185.242.245.27:44875",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-11 09:43:35",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810950": [
        {
            "ioc_value": "158.94.210.70:22532",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-11 09:43:20",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810414": [
        {
            "ioc_value": "31.57.184.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-10 19:44:31",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810410": [
        {
            "ioc_value": "195.123.240.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810411": [
        {
            "ioc_value": "195.123.240.236:8274",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-10 19:43:45",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810408": [
        {
            "ioc_value": "189.34.188.6:5406",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810409": [
        {
            "ioc_value": "189.34.188.6:5407",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-10 19:43:39",
            "last_seen_utc": "2026-08-11 02:44:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1810170": [
        {
            "ioc_value": "57.158.27.132:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-10 09:44:56",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809754": [
        {
            "ioc_value": "213.130.25.141:44333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-05-09 19:43:46",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,NetSupport,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809750": [
        {
            "ioc_value": "168.144.89.48:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-09 19:43:24",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809039": [
        {
            "ioc_value": "209.38.100.109:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 19:43:41",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809038": [
        {
            "ioc_value": "193.42.24.165:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 19:43:36",
            "last_seen_utc": "2026-08-11 02:44:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809033": [
        {
            "ioc_value": "180.97.214.70:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-08 19:43:28",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1809029": [
        {
            "ioc_value": "160.25.82.142:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 19:43:19",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808650": [
        {
            "ioc_value": "45.56.91.55:2005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:45",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808648": [
        {
            "ioc_value": "31.57.216.62:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-08 08:43:42",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808643": [
        {
            "ioc_value": "209.38.110.161:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:21",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808637": [
        {
            "ioc_value": "178.104.186.90:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-08 08:43:13",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808628": [
        {
            "ioc_value": "113.31.118.180:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-08 08:43:05",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808623": [
        {
            "ioc_value": "104.243.248.63:1802",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-08 08:43:04",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1808286": [
        {
            "ioc_value": "101.33.225.32:8011",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-07 20:44:32",
            "last_seen_utc": "2026-08-11 02:46:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807868": [
        {
            "ioc_value": "27.102.137.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 20:53:22",
            "last_seen_utc": "2026-08-11 02:45:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "Remcos,RemcosRAT,Remvio,Socmer",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1807906": [
        {
            "ioc_value": "45.207.192.190:30078",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:39",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807905": [
        {
            "ioc_value": "207.56.226.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:29",
            "last_seen_utc": "2026-08-09 08:47:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807904": [
        {
            "ioc_value": "117.72.168.103:16337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-06 20:45:09",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807845": [
        {
            "ioc_value": "31.57.216.62:14641",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-05-06 18:43:51",
            "last_seen_utc": "2026-08-09 08:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT,RemcosRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807842": [
        {
            "ioc_value": "154.18.238.18:8848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-06 18:43:14",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1807538": [
        {
            "ioc_value": "31.57.184.154:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-06 08:43:54",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806901": [
        {
            "ioc_value": "172.245.156.179:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-05 08:44:56",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806229": [
        {
            "ioc_value": "8.130.80.145:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:45:07",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806228": [
        {
            "ioc_value": "154.219.115.123:61443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:43",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1806227": [
        {
            "ioc_value": "119.29.198.193:8555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-04 20:44:36",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805766": [
        {
            "ioc_value": "82.165.79.60:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:13",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805765": [
        {
            "ioc_value": "82.165.79.60:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-05-04 08:44:12",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Sliver",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805757": [
        {
            "ioc_value": "163.181.45.55:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-04 08:43:16",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805268": [
        {
            "ioc_value": "151.245.90.45:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:29",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1805267": [
        {
            "ioc_value": "ap.johamp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-03 12:44:08",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804968": [
        {
            "ioc_value": "203.160.54.22:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:31",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804965": [
        {
            "ioc_value": "h67as5d5x.m6p3wca1.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 20:44:06",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804928": [
        {
            "ioc_value": "38.147.173.24:8562",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-02 18:43:44",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804853": [
        {
            "ioc_value": "47.101.172.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-02 14:44:30",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804732": [
        {
            "ioc_value": "8.160.216.91:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:53",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1804719": [
        {
            "ioc_value": "124.95.172.200:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-02 08:43:06",
            "last_seen_utc": "2026-08-11 02:43:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803956": [
        {
            "ioc_value": "https://arsimonopa.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:17",
            "last_seen_utc": "2026-08-11 03:28:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1803960": [
        {
            "ioc_value": "https://lemonimonakio.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-05-02 05:24:15",
            "last_seen_utc": "2026-08-11 03:18:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1803896": [
        {
            "ioc_value": "89.114.115.200:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 18:43:58",
            "last_seen_utc": "2026-08-11 02:46:34",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803894": [
        {
            "ioc_value": "59.152.212.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 18:43:53",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803881": [
        {
            "ioc_value": "45.10.164.177:45123",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 18:43:45",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803874": [
        {
            "ioc_value": "31.57.184.154:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 18:43:41",
            "last_seen_utc": "2026-08-11 02:45:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803866": [
        {
            "ioc_value": "195.88.191.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803867": [
        {
            "ioc_value": "195.88.191.41:7666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-05-01 18:43:24",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803858": [
        {
            "ioc_value": "185.212.128.80:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 18:43:19",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803841": [
        {
            "ioc_value": "103.79.79.105:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-05-01 18:43:03",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,PupyRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803693": [
        {
            "ioc_value": "8.222.192.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:50",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803689": [
        {
            "ioc_value": "47.236.91.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 14:44:44",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803670": [
        {
            "ioc_value": "frr.ambil-disini.web.id",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-08-11 03:20:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803671": [
        {
            "ioc_value": "https://frr.ambil-disini.web.id/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-05-01 14:30:24",
            "last_seen_utc": "2026-08-11 03:20:12",
            "confidence_level": 100,
            "is_compromised": true,
            "reference": null,
            "tags": "vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1803513": [
        {
            "ioc_value": "64.89.163.114:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 08:43:48",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803500": [
        {
            "ioc_value": "47.103.106.26:2333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 08:43:44",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803473": [
        {
            "ioc_value": "178.128.252.142:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:16",
            "last_seen_utc": "2026-08-11 02:44:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803448": [
        {
            "ioc_value": "111.229.144.163:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 08:43:05",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803387": [
        {
            "ioc_value": "203.160.54.22:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-05-01 07:08:49",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803286": [
        {
            "ioc_value": "94.176.3.228:48765",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-08-11 02:46:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803291": [
        {
            "ioc_value": "98.97.125.70:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:32",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803279": [
        {
            "ioc_value": "91.202.233.153:43555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803280": [
        {
            "ioc_value": "91.215.85.151:47653",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:31",
            "last_seen_utc": "2026-08-11 02:46:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803276": [
        {
            "ioc_value": "85.155.186.2:3821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:30",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803262": [
        {
            "ioc_value": "79.135.160.20:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:28",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803257": [
        {
            "ioc_value": "66.163.115.78:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:27",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803254": [
        {
            "ioc_value": "62.81.188.1:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803255": [
        {
            "ioc_value": "66.163.115.78:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803256": [
        {
            "ioc_value": "66.163.115.78:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:26",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803246": [
        {
            "ioc_value": "46.101.77.223:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:25",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803239": [
        {
            "ioc_value": "45.155.69.175:42455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803240": [
        {
            "ioc_value": "45.56.91.55:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Covenant,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803244": [
        {
            "ioc_value": "45.81.243.52:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:24",
            "last_seen_utc": "2026-08-11 02:46:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803235": [
        {
            "ioc_value": "45.125.67.171:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803238": [
        {
            "ioc_value": "45.155.69.106:42211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:23",
            "last_seen_utc": "2026-08-11 02:45:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803231": [
        {
            "ioc_value": "43.134.133.177:8445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-11 02:45:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803232": [
        {
            "ioc_value": "43.142.77.170:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803233": [
        {
            "ioc_value": "43.142.77.170:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803234": [
        {
            "ioc_value": "43.160.225.40:39001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:22",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803218": [
        {
            "ioc_value": "222.255.100.119:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803219": [
        {
            "ioc_value": "23.227.203.6:42235",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-08-11 02:45:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803222": [
        {
            "ioc_value": "31.57.184.154:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:20",
            "last_seen_utc": "2026-08-11 02:45:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803211": [
        {
            "ioc_value": "216.107.208.250:10444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-11 02:44:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803215": [
        {
            "ioc_value": "219.142.15.101:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803216": [
        {
            "ioc_value": "220.231.47.163:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803217": [
        {
            "ioc_value": "221.130.42.19:4353",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.danabot",
            "malware_alias": "DanaTools",
            "malware_printable": "DanaBot",
            "first_seen_utc": "2026-05-01 02:43:19",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DanBot,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803205": [
        {
            "ioc_value": "208.249.244.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803206": [
        {
            "ioc_value": "209.151.145.164:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-05-01 02:43:18",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803202": [
        {
            "ioc_value": "202.95.17.188:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-08-11 02:44:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803203": [
        {
            "ioc_value": "206.189.40.107:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:17",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803180": [
        {
            "ioc_value": "185.242.3.83:9909",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803181": [
        {
            "ioc_value": "185.247.224.40:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:14",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803173": [
        {
            "ioc_value": "185.212.128.81:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803174": [
        {
            "ioc_value": "185.212.129.23:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803176": [
        {
            "ioc_value": "185.212.129.29:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803177": [
        {
            "ioc_value": "185.212.129.30:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.evilginx",
            "malware_alias": null,
            "malware_printable": "Evilginx",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-11 02:44:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Evilginx,EvilGoPhish",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803178": [
        {
            "ioc_value": "185.213.20.250:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-11 02:44:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803179": [
        {
            "ioc_value": "185.242.245.120:42534",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:13",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803166": [
        {
            "ioc_value": "180.184.29.135:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803167": [
        {
            "ioc_value": "182.255.45.114:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:12",
            "last_seen_utc": "2026-08-11 02:44:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803162": [
        {
            "ioc_value": "178.16.52.22:8396",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:11",
            "last_seen_utc": "2026-08-11 02:44:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803152": [
        {
            "ioc_value": "172.111.162.252:3030",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803153": [
        {
            "ioc_value": "172.9.165.216:8096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:09",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803141": [
        {
            "ioc_value": "154.219.115.123:60001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803146": [
        {
            "ioc_value": "161.248.179.92:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803147": [
        {
            "ioc_value": "162.14.124.25:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:08",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803134": [
        {
            "ioc_value": "149.104.28.204:3656",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:07",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803127": [
        {
            "ioc_value": "142.93.88.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-05-01 02:43:06",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Havoc",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803124": [
        {
            "ioc_value": "138.124.113.131:4211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:05",
            "last_seen_utc": "2026-08-11 02:43:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803114": [
        {
            "ioc_value": "115.42.60.122:5440",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803115": [
        {
            "ioc_value": "117.72.101.55:9520",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2026-05-01 02:43:04",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CHAOS,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803109": [
        {
            "ioc_value": "103.75.190.47:54630",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "DCRat,drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803110": [
        {
            "ioc_value": "104.234.174.93:57712",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-08-11 02:43:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1803113": [
        {
            "ioc_value": "115.190.247.97:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-05-01 02:43:03",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1802897": [
        {
            "ioc_value": "82.156.219.31:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-30 18:43:45",
            "last_seen_utc": "2026-08-11 02:47:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800528": [
        {
            "ioc_value": "http://pillow.riverbridge.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 19:14:08",
            "last_seen_utc": "2026-08-11 03:19:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800513": [
        {
            "ioc_value": "91.92.242.236:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:36:03",
            "last_seen_utc": "2026-08-11 03:09:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://tracker.viriback.com/index.php?q=91.92.242.236",
            "tags": "Amadey,ViriBack",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800509": [
        {
            "ioc_value": "pillow.riverbridge.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-26 18:19:19",
            "last_seen_utc": "2026-08-11 03:19:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/2199baf11d50dd10555f8aec122178e03b62570fc0d4614a8e928978dc547154/",
            "tags": "ipocalur,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1800411": [
        {
            "ioc_value": "http://91.92.242.236/oPvjr94jfe/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-26 18:11:00",
            "last_seen_utc": "2026-08-11 03:26:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "54e64e,amadey,c2",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1797248": [
        {
            "ioc_value": "psy.flise-mesteren.dk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:06",
            "last_seen_utc": "2026-08-11 03:19:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1797247": [
        {
            "ioc_value": "https://psy.flise-mesteren.dk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-24 15:18:01",
            "last_seen_utc": "2026-08-11 03:19:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "r88vry,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796426": [
        {
            "ioc_value": "http://196.251.107.248/kont2rt/index.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.amadey",
            "malware_alias": null,
            "malware_printable": "Amadey",
            "first_seen_utc": "2026-04-23 04:45:34",
            "last_seen_utc": "2026-08-11 03:28:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amadey",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796313": [
        {
            "ioc_value": "192.210.174.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 20:53:22",
            "last_seen_utc": "2026-08-11 02:47:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796097": [
        {
            "ioc_value": "47.94.162.43:2222",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-22 14:30:19",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1796068": [
        {
            "ioc_value": "wrath.bottlevacuum.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:13",
            "last_seen_utc": "2026-08-11 03:19:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1796067": [
        {
            "ioc_value": "http://wrath.bottlevacuum.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-22 11:17:09",
            "last_seen_utc": "2026-08-11 03:19:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "opiusra,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1794638": [
        {
            "ioc_value": "http://213.5.130.87",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-19 18:25:29",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793645": [
        {
            "ioc_value": "http://213.5.130.147",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-17 18:15:06",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1793617": [
        {
            "ioc_value": "ask.shurimaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:27",
            "last_seen_utc": "2026-08-11 03:18:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1793616": [
        {
            "ioc_value": "https://ask.shurimaster.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-17 17:13:25",
            "last_seen_utc": "2026-08-11 03:18:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "a10fsw,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792850": [
        {
            "ioc_value": "pir.rapidphonebuyer.co.uk",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:58",
            "last_seen_utc": "2026-08-11 03:16:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792849": [
        {
            "ioc_value": "https://pir.rapidphonebuyer.co.uk/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 16:13:56",
            "last_seen_utc": "2026-08-11 03:16:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "d0b0p,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792719": [
        {
            "ioc_value": "gusto.brothbridge.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:20",
            "last_seen_utc": "2026-08-11 03:19:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792718": [
        {
            "ioc_value": "http://gusto.brothbridge.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-16 11:16:17",
            "last_seen_utc": "2026-08-11 03:19:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odiznrio,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792707": [
        {
            "ioc_value": "43.167.177.224:7778",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 10:56:58",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1792532": [
        {
            "ioc_value": "bxx2rghe05kng.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-16 02:43:39",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791747": [
        {
            "ioc_value": "http://107.189.24.190:80",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 11:43:19",
            "last_seen_utc": "2026-08-11 03:13:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "gr00n1,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791738": [
        {
            "ioc_value": "139.224.23.63:8866",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-15 11:39:45",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1791688": [
        {
            "ioc_value": "venom.summertunnel.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:17",
            "last_seen_utc": "2026-08-11 03:18:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1791687": [
        {
            "ioc_value": "http://venom.summertunnel.shop",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-15 08:15:13",
            "last_seen_utc": "2026-08-11 03:18:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "ozpifus,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790171": [
        {
            "ioc_value": "dzodu.sparklingideas.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:23",
            "last_seen_utc": "2026-08-11 03:18:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790170": [
        {
            "ioc_value": "http://dzodu.sparklingideas.space",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:11:18",
            "last_seen_utc": "2026-08-11 03:18:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "odzdkzo,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1790169": [
        {
            "ioc_value": "http://kdije.weirdthings.site",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-14 14:10:11",
            "last_seen_utc": "2026-08-11 03:15:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "okfueh,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1785064": [
        {
            "ioc_value": "pre.hifive.net.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:47:21",
            "last_seen_utc": "2026-08-11 03:17:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1785049": [
        {
            "ioc_value": "https://pre.hifive.net.au/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-13 07:46:34",
            "last_seen_utc": "2026-08-11 03:17:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1784558": [
        {
            "ioc_value": "47.104.248.7:8884",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-12 06:34:43",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1783375": [
        {
            "ioc_value": "39.102.125.11:4435",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-09 14:48:47",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782524": [
        {
            "ioc_value": "82.165.179.9:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:06:40",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/4c3b97c157d08ee298edb5d30fa86a3b90b04fedfbe517e7e0307b6013eacbf0/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782522": [
        {
            "ioc_value": "82.165.179.9:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-04-07 23:00:12",
            "last_seen_utc": "2026-08-11 02:46:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1782182": [
        {
            "ioc_value": "dzdi.serendipityhub.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:46:05",
            "last_seen_utc": "2026-08-11 03:17:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1782152": [
        {
            "ioc_value": "http://dzdi.serendipityhub.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-07 07:43:55",
            "last_seen_utc": "2026-08-11 03:17:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1781907": [
        {
            "ioc_value": "43.139.108.161:8192",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-06 18:49:49",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Agentemis,BEACON,C2,Cobalt Strike,CobaltStrike,cobeacon",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1781225": [
        {
            "ioc_value": "111.230.217.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:05",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1781224": [
        {
            "ioc_value": "109.244.130.113:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-04-04 20:44:01",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1780847": [
        {
            "ioc_value": "https://dnsnewtds.shop/jsrepo",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-03 20:00:46",
            "last_seen_utc": "2026-08-10 05:32:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1780846": [
        {
            "ioc_value": "dnsnewtds.shop",
            "ioc_type": "domain",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-03 20:00:36",
            "last_seen_utc": "2026-08-10 05:32:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1780845": [
        {
            "ioc_value": "https://ntdnewtds.shop/jsrepo",
            "ioc_type": "url",
            "threat_type": "payload_delivery",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-04-03 19:59:55",
            "last_seen_utc": "2026-08-10 05:32:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "ClickFix",
            "anonymous": 0,
            "reporter": "HuntYethHounds"
        }
    ],
    "1780720": [
        {
            "ioc_value": "hor.kaitorinihon.jp",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:13:22",
            "last_seen_utc": "2026-08-11 03:16:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1780716": [
        {
            "ioc_value": "https://hor.kaitorinihon.jp/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-04-03 16:12:59",
            "last_seen_utc": "2026-08-11 03:16:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777607": [
        {
            "ioc_value": "pn2.skfilmsint.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-08-11 03:15:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777609": [
        {
            "ioc_value": "gre.syslicense.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-08-11 03:15:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777611": [
        {
            "ioc_value": "fefeo.iknowthat.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:29",
            "last_seen_utc": "2026-08-11 03:15:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777601": [
        {
            "ioc_value": "https://pn2.skfilmsint.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-08-11 03:15:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777603": [
        {
            "ioc_value": "https://gre.syslicense.net/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-08-11 03:15:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777605": [
        {
            "ioc_value": "http://fefeo.iknowthat.space/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-27 21:24:17",
            "last_seen_utc": "2026-08-11 03:15:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1777296": [
        {
            "ioc_value": "185.242.3.83:2202",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-27 12:01:30",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.242.3.83",
            "tags": "AS60223,AsyncRAT,C2,censys,NETIFACE-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774903": [
        {
            "ioc_value": "37.72.172.58:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-24 12:01:13",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774898": [
        {
            "ioc_value": "47.92.208.27:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-24 12:00:35",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.92.208.27",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774508": [
        {
            "ioc_value": "thisisafalsepositive.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-24 07:09:06",
            "last_seen_utc": "2026-08-11 03:08:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://app.any.run/tasks/1ef52a2b-2735-48b0-a673-8432a9b77898",
            "tags": "C2,SilentNet",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1774595": [
        {
            "ioc_value": "154.83.12.132:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-23 21:06:09",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1774355": [
        {
            "ioc_value": "kdije.weirdthings.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 13:42:00",
            "last_seen_utc": "2026-08-11 03:15:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774216": [
        {
            "ioc_value": "msi.swadeshcomputer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:02:27",
            "last_seen_utc": "2026-08-11 03:14:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774200": [
        {
            "ioc_value": "https://msi.swadeshcomputer.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-23 08:01:55",
            "last_seen_utc": "2026-08-11 03:14:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1774089": [
        {
            "ioc_value": "195.250.25.176:58101",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-23 04:01:29",
            "last_seen_utc": "2026-08-11 02:44:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.250.25.176",
            "tags": "AdaptixC2,AS36454,C2,censys,WHG-DAL",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1774088": [
        {
            "ioc_value": "23.227.199.67:42215",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-23 04:01:28",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.199.67",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1773536": [
        {
            "ioc_value": "156.239.252.191:448",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-22 18:02:20",
            "last_seen_utc": "2026-08-11 02:47:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "BEACON,C2,CobaltStrike,Shodan",
            "anonymous": 0,
            "reporter": "whoamix302"
        }
    ],
    "1773754": [
        {
            "ioc_value": "138.226.236.52:13212",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-22 12:01:29",
            "last_seen_utc": "2026-08-11 02:43:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/138.226.236.52",
            "tags": "AdaptixC2,AS205775,C2,censys,NEONCORENETWORKS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1772372": [
        {
            "ioc_value": "pr2.codetohaven.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:59",
            "last_seen_utc": "2026-08-11 03:14:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1772370": [
        {
            "ioc_value": "https://pr2.codetohaven.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-20 13:59:49",
            "last_seen_utc": "2026-08-11 03:14:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1771846": [
        {
            "ioc_value": "51.222.87.16:433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 04:19:09",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771843": [
        {
            "ioc_value": "cdn.sys-update.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-20 04:08:17",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771791": [
        {
            "ioc_value": "8.136.13.87:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-20 00:02:12",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.136.13.87",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771714": [
        {
            "ioc_value": "45.136.13.247:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:51",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.136.13.247",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771713": [
        {
            "ioc_value": "167.17.47.121:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-19 20:02:47",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.17.47.121",
            "tags": "AdaptixC2,AS43180,C2,censys,TRUNKNETWORKS-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1771456": [
        {
            "ioc_value": "dhzuadd.hellothere.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:25",
            "last_seen_utc": "2026-08-11 03:14:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1771455": [
        {
            "ioc_value": "https://dhzuadd.hellothere.sbs",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-19 13:11:20",
            "last_seen_utc": "2026-08-11 03:14:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drkfiz,Vidar",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1768644": [
        {
            "ioc_value": "35.179.229.71:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-03-16 20:01:10",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/35.179.229.71",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1768638": [
        {
            "ioc_value": "64.227.105.70:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-16 20:01:02",
            "last_seen_utc": "2026-08-11 02:46:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.227.105.70",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1767990": [
        {
            "ioc_value": "43.155.169.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-16 12:00:11",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.155.169.245",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1766764": [
        {
            "ioc_value": "202.191.67.71:50003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-03-15 04:01:14",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/202.191.67.71",
            "tags": "AdaptixC2,AS131262,C2,censys,KELNET-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1765792": [
        {
            "ioc_value": "39.103.91.52:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-14 08:06:08",
            "last_seen_utc": "2026-08-09 08:47:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1765787": [
        {
            "ioc_value": "5.101.82.60:2509",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-14 08:00:55",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1765444": [
        {
            "ioc_value": "pan.paihost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:06:16",
            "last_seen_utc": "2026-08-11 03:13:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1765442": [
        {
            "ioc_value": "https://pan.paihost.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-13 15:05:58",
            "last_seen_utc": "2026-08-11 03:13:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1764276": [
        {
            "ioc_value": "46.151.182.205:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-13 04:01:11",
            "last_seen_utc": "2026-08-11 02:46:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.151.182.205",
            "tags": "AS205759,AsyncRAT,C2,censys,GHOSTYNETWORKS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1763543": [
        {
            "ioc_value": "159.138.31.252:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-11 16:01:48",
            "last_seen_utc": "2026-08-11 02:43:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/159.138.31.252",
            "tags": "AS136907,C2,censys,HWCLOUDS-AS-AP,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1763170": [
        {
            "ioc_value": "60.247.206.23:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 07:03:38",
            "last_seen_utc": "2026-08-11 02:47:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1763116": [
        {
            "ioc_value": "118.25.10.65:65010",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-11 04:00:36",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.10.65",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762899": [
        {
            "ioc_value": "https://nonobody123.com",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-03-10 18:04:42",
            "last_seen_utc": "2026-08-11 03:09:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://tria.ge/260310-t5ja8aew7y",
            "tags": "C2,stealc,stealer,triage",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762854": [
        {
            "ioc_value": "85.206.168.238:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2026-03-10 16:00:58",
            "last_seen_utc": "2026-08-11 02:46:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/85.206.168.238",
            "tags": "AS61272,C2,censys,IST-AS,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762492": [
        {
            "ioc_value": "107.172.3.15:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-10 00:01:13",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.3.15",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1762153": [
        {
            "ioc_value": "ooe.myserver.com.bd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:37",
            "last_seen_utc": "2026-08-11 03:13:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1762131": [
        {
            "ioc_value": "https://ooe.myserver.com.bd/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-09 09:29:17",
            "last_seen_utc": "2026-08-11 03:13:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1760216": [
        {
            "ioc_value": "51.222.87.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-03-06 08:00:30",
            "last_seen_utc": "2026-08-10 08:08:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.222.87.16",
            "tags": "AS16276,C2,censys,CobaltStrike,cs-watermark-426352781,OVH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1758456": [
        {
            "ioc_value": "http://213.5.130.197",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:58",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758457": [
        {
            "ioc_value": "http://213.5.130.154",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:57",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758458": [
        {
            "ioc_value": "http://213.5.130.200",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:56",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758459": [
        {
            "ioc_value": "http://213.5.130.131",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:55",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758460": [
        {
            "ioc_value": "http://213.5.130.179",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758461": [
        {
            "ioc_value": "http://213.5.130.189",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-05 06:17:54",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1758006": [
        {
            "ioc_value": "70.153.18.45:10002",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-03-04 04:01:12",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/70.153.18.45",
            "tags": "AS8075,censys,EvilGoPhish,MICROSOFT-CORP-MSN-AS-BLOCK,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1756955": [
        {
            "ioc_value": "104.243.248.63:1801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-03-02 15:30:09",
            "last_seen_utc": "2026-08-11 02:43:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1756664": [
        {
            "ioc_value": "ctl.it-bd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:31:49",
            "last_seen_utc": "2026-08-11 03:12:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1756622": [
        {
            "ioc_value": "https://ctl.it-bd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-03-02 09:30:33",
            "last_seen_utc": "2026-08-11 03:12:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1756333": [
        {
            "ioc_value": "171.22.181.114:38990",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "elf.pink",
            "malware_alias": null,
            "malware_printable": "Pink",
            "first_seen_utc": "2026-03-01 14:27:15",
            "last_seen_utc": "2026-08-11 03:27:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Pink",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1754813": [
        {
            "ioc_value": "47.120.20.86:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 20:02:24",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.20.86",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1754671": [
        {
            "ioc_value": "115.190.250.28:5521",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-25 19:01:08",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.250.28",
            "tags": "AS137718,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754344": [
        {
            "ioc_value": "23.88.110.42:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.poshc2",
            "malware_alias": null,
            "malware_printable": "PoshC2",
            "first_seen_utc": "2026-02-24 23:00:43",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.88.110.42",
            "tags": "AS24940,C2,censys,HETZNER-AS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1754178": [
        {
            "ioc_value": "169.40.135.36:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-24 12:02:30",
            "last_seen_utc": "2026-08-11 02:43:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/169.40.135.36",
            "tags": "AdaptixC2,AS209274,C2,censys,KRAKEN-NETWORK-ISP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1753846": [
        {
            "ioc_value": "64.89.161.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-23 23:00:07",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.89.161.183",
            "tags": "AS205759,C2,censys,GHOSTYNETWORKS",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1753479": [
        {
            "ioc_value": "glo.gadgetwalabd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:07:22",
            "last_seen_utc": "2026-08-11 03:12:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1753432": [
        {
            "ioc_value": "https://glo.gadgetwalabd.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-23 10:06:47",
            "last_seen_utc": "2026-08-11 03:12:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1752688": [
        {
            "ioc_value": "149.28.242.44:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-23 00:02:15",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.242.44",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1751483": [
        {
            "ioc_value": "45.116.104.104:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-21 08:01:40",
            "last_seen_utc": "2026-08-09 08:45:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.116.104.104",
            "tags": "AS215481,C2,censys,FLEXYNODE-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1751453": [
        {
            "ioc_value": "47.104.159.246:18443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-21 03:00:07",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.104.159.246",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751104": [
        {
            "ioc_value": "107.172.217.220:12096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-20 11:00:06",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.172.217.220",
            "tags": "AS36352,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1751083": [
        {
            "ioc_value": "185.180.198.3:2025",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1751084": [
        {
            "ioc_value": "185.180.198.3:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-02-20 08:47:26",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1751080": [
        {
            "ioc_value": "163.181.208.79:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-20 08:46:17",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1749811": [
        {
            "ioc_value": "66.42.49.168:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-17 07:00:18",
            "last_seen_utc": "2026-08-11 02:46:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/66.42.49.168",
            "tags": "AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1749217": [
        {
            "ioc_value": "111.228.4.54:4455",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-16 09:05:30",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/111.228.4.54#4455",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1748314": [
        {
            "ioc_value": "27.221.15.199:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-02-14 18:46:07",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1747540": [
        {
            "ioc_value": "gor.emiraride.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:35",
            "last_seen_utc": "2026-08-11 03:12:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747538": [
        {
            "ioc_value": "https://gor.emiraride.com/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2026-02-13 14:01:02",
            "last_seen_utc": "2026-08-11 03:12:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1747121": [
        {
            "ioc_value": "117.72.191.140:8028",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-13 06:59:13",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.191.140#8028",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1746911": [
        {
            "ioc_value": "175.192.75.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2026-02-12 16:01:27",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/175.192.75.105",
            "tags": "AS4766,C2,censys,KIXS-AS-KR,Netsupport,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1743398": [
        {
            "ioc_value": "192.3.233.166:59850",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 16:00:16",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.3.233.166",
            "tags": "AS-COLOCROSSING,AS36352,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1743395": [
        {
            "ioc_value": "1.15.25.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:41",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743391": [
        {
            "ioc_value": "106.52.208.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743392": [
        {
            "ioc_value": "106.13.137.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743393": [
        {
            "ioc_value": "101.43.2.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743394": [
        {
            "ioc_value": "101.133.148.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:40",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743388": [
        {
            "ioc_value": "115.190.178.249:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743389": [
        {
            "ioc_value": "114.132.150.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743390": [
        {
            "ioc_value": "110.40.176.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:39",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743386": [
        {
            "ioc_value": "120.48.50.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743387": [
        {
            "ioc_value": "117.72.214.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:37",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743381": [
        {
            "ioc_value": "124.223.199.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743382": [
        {
            "ioc_value": "124.221.32.87:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743383": [
        {
            "ioc_value": "124.220.48.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743384": [
        {
            "ioc_value": "124.220.164.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743385": [
        {
            "ioc_value": "121.41.167.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:36",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743378": [
        {
            "ioc_value": "152.136.139.105:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743379": [
        {
            "ioc_value": "129.204.103.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743380": [
        {
            "ioc_value": "124.223.47.219:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:35",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743374": [
        {
            "ioc_value": "172.245.215.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743375": [
        {
            "ioc_value": "165.154.125.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743376": [
        {
            "ioc_value": "156.233.233.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743377": [
        {
            "ioc_value": "154.201.91.224:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:34",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743370": [
        {
            "ioc_value": "38.190.224.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743371": [
        {
            "ioc_value": "222.255.214.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743372": [
        {
            "ioc_value": "192.252.187.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743373": [
        {
            "ioc_value": "178.16.52.194:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:33",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743365": [
        {
            "ioc_value": "43.139.146.100:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743366": [
        {
            "ioc_value": "43.133.41.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743367": [
        {
            "ioc_value": "42.192.49.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743368": [
        {
            "ioc_value": "39.107.85.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743369": [
        {
            "ioc_value": "39.106.144.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:32",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743363": [
        {
            "ioc_value": "47.100.168.4:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743364": [
        {
            "ioc_value": "43.139.169.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:31",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743362": [
        {
            "ioc_value": "47.111.146.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:30",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743358": [
        {
            "ioc_value": "47.243.175.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743359": [
        {
            "ioc_value": "47.239.188.48:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743360": [
        {
            "ioc_value": "47.122.30.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743361": [
        {
            "ioc_value": "47.122.1.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:29",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743356": [
        {
            "ioc_value": "61.166.154.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-08-11 03:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743357": [
        {
            "ioc_value": "49.235.177.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:28",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743353": [
        {
            "ioc_value": "81.70.255.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743354": [
        {
            "ioc_value": "81.69.98.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743355": [
        {
            "ioc_value": "8.210.78.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:27",
            "last_seen_utc": "2026-08-11 03:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743351": [
        {
            "ioc_value": "83.229.126.65:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743352": [
        {
            "ioc_value": "81.71.159.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:26",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743349": [
        {
            "ioc_value": "83.229.123.61:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743350": [
        {
            "ioc_value": "83.229.126.183:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:15",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743348": [
        {
            "ioc_value": "8.153.205.30:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:14",
            "last_seen_utc": "2026-08-11 03:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743347": [
        {
            "ioc_value": "8.137.149.67:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:13",
            "last_seen_utc": "2026-08-11 03:21:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743344": [
        {
            "ioc_value": "47.93.28.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743345": [
        {
            "ioc_value": "60.205.139.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-08-11 03:21:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743346": [
        {
            "ioc_value": "lcowpowerlite.italynorth.cloudapp.azure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:12",
            "last_seen_utc": "2026-08-11 03:21:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743340": [
        {
            "ioc_value": "47.109.198.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-11 03:21:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743341": [
        {
            "ioc_value": "47.120.70.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743342": [
        {
            "ioc_value": "47.121.137.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743343": [
        {
            "ioc_value": "47.121.29.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:11",
            "last_seen_utc": "2026-08-11 03:21:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743336": [
        {
            "ioc_value": "45.115.236.152:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743338": [
        {
            "ioc_value": "47.107.136.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743339": [
        {
            "ioc_value": "47.109.145.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:10",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743333": [
        {
            "ioc_value": "192.140.176.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-08-11 03:21:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743334": [
        {
            "ioc_value": "36.140.162.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-08-11 03:21:07",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743335": [
        {
            "ioc_value": "39.105.165.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:09",
            "last_seen_utc": "2026-08-11 03:21:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743330": [
        {
            "ioc_value": "152.32.251.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743331": [
        {
            "ioc_value": "154.201.74.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743332": [
        {
            "ioc_value": "179.43.186.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:08",
            "last_seen_utc": "2026-08-11 03:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743326": [
        {
            "ioc_value": "139.196.41.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-11 03:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743327": [
        {
            "ioc_value": "139.224.16.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-11 03:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743328": [
        {
            "ioc_value": "14.103.175.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-11 03:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743329": [
        {
            "ioc_value": "150.187.25.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:07",
            "last_seen_utc": "2026-08-11 03:21:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743322": [
        {
            "ioc_value": "120.48.168.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-11 03:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743323": [
        {
            "ioc_value": "121.40.18.128:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-11 03:21:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743324": [
        {
            "ioc_value": "122.51.93.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-11 03:21:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743325": [
        {
            "ioc_value": "134.122.140.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:06",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743320": [
        {
            "ioc_value": "117.72.102.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743321": [
        {
            "ioc_value": "117.72.242.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:05",
            "last_seen_utc": "2026-08-11 03:21:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743318": [
        {
            "ioc_value": "113.44.67.52:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-08-11 03:21:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743319": [
        {
            "ioc_value": "115.190.161.178:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:04",
            "last_seen_utc": "2026-08-11 03:21:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743314": [
        {
            "ioc_value": "106.38.201.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-11 03:21:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743315": [
        {
            "ioc_value": "106.75.162.108:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-11 03:21:02",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743316": [
        {
            "ioc_value": "106.75.215.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743317": [
        {
            "ioc_value": "106.75.224.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:03",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743312": [
        {
            "ioc_value": "106.12.219.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-08-11 03:21:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1743313": [
        {
            "ioc_value": "106.13.29.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-02-08 15:42:02",
            "last_seen_utc": "2026-08-11 03:21:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1742595": [
        {
            "ioc_value": "174.138.86.141:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-07 03:00:18",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/174.138.86.141",
            "tags": "AS14061,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741587": [
        {
            "ioc_value": "57.158.27.132:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2026-02-05 13:01:59",
            "last_seen_utc": "2026-08-11 02:46:15",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/57.158.27.132#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1741375": [
        {
            "ioc_value": "37.72.172.58:6066",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-02-05 06:34:37",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "",
            "tags": "AS29802,asyncrat,c2,fofa,RAT",
            "anonymous": 0,
            "reporter": "oxygen28"
        }
    ],
    "1741222": [
        {
            "ioc_value": "3.121.234.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 15:54:23",
            "last_seen_utc": "2026-08-11 02:45:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.121.234.29",
            "tags": "AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1741132": [
        {
            "ioc_value": "172.174.234.34:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-02-04 11:00:54",
            "last_seen_utc": "2026-08-11 02:43:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.174.234.34",
            "tags": "AS8075,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1740953": [
        {
            "ioc_value": "188.166.244.201:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-02-04 00:02:27",
            "last_seen_utc": "2026-08-11 02:44:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/188.166.244.201",
            "tags": "AdaptixC2,AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739255": [
        {
            "ioc_value": "98.85.71.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-31 00:05:33",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/98.85.71.175",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739209": [
        {
            "ioc_value": "47.115.193.52:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2026-01-30 18:54:11",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1739169": [
        {
            "ioc_value": "167.99.208.145:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-30 16:05:29",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.208.145",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739163": [
        {
            "ioc_value": "107.150.105.91:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 16:04:48",
            "last_seen_utc": "2026-08-11 03:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.150.105.91",
            "tags": "AS135377,C2,censys,CobaltStrike,cs-watermark-666666666,UCLOUD-HK-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1739009": [
        {
            "ioc_value": "111.92.243.40:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-30 08:04:49",
            "last_seen_utc": "2026-08-11 03:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.92.243.40",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1738921": [
        {
            "ioc_value": "45.82.85.50:13063",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2026-01-30 02:55:25",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1738909": [
        {
            "ioc_value": "68.64.178.201:54321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-30 00:06:02",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.178.201",
            "tags": "AdaptixC2,AS139659,C2,censys,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1737790": [
        {
            "ioc_value": "47.120.46.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-26 23:00:09",
            "last_seen_utc": "2026-08-11 03:21:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.46.230",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1737664": [
        {
            "ioc_value": "https://fluraresto.me/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-08-11 03:24:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1737665": [
        {
            "ioc_value": "https://mastralakkot.live/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2026-01-26 13:57:13",
            "last_seen_utc": "2026-08-11 03:15:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Latrodectus",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1737455": [
        {
            "ioc_value": "167.179.76.179:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:49:35",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1737454": [
        {
            "ioc_value": "ns1.ns-apache.jo3.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-25 22:48:35",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736034": [
        {
            "ioc_value": "158.158.8.193:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.bianlian",
            "malware_alias": null,
            "malware_printable": "BianLian",
            "first_seen_utc": "2026-01-23 08:45:57",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Bianlian,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1736014": [
        {
            "ioc_value": "47.120.32.72:8075",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-23 08:04:06",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.120.32.72",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735522": [
        {
            "ioc_value": "176.31.71.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 12:04:28",
            "last_seen_utc": "2026-08-11 02:44:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/176.31.71.168",
            "tags": "AS16276,C2,censys,OVH,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735412": [
        {
            "ioc_value": "34.64.98.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-22 04:04:19",
            "last_seen_utc": "2026-08-11 02:45:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/34.64.98.201",
            "tags": "AS396982,C2,censys,GOOGLE-CLOUD-PLATFORM,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1735342": [
        {
            "ioc_value": "54.145.56.188:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-21 20:04:36",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.145.56.188",
            "tags": "AMAZON-AES,AS14618,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734935": [
        {
            "ioc_value": "37.72.168.189:42334",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2026-01-20 20:05:01",
            "last_seen_utc": "2026-08-11 02:45:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.168.189",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734893": [
        {
            "ioc_value": "136.24.173.249:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-20 16:04:24",
            "last_seen_utc": "2026-08-11 02:43:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/136.24.173.249",
            "tags": "AS19165,C2,censys,Mythic,WEBPASS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734081": [
        {
            "ioc_value": "103.79.79.105:8444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-18 00:03:59",
            "last_seen_utc": "2026-08-11 02:43:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.79.79.105",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1734053": [
        {
            "ioc_value": "43.139.50.42:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-17 20:52:32",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1732709": [
        {
            "ioc_value": "117.72.178.246:4848",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-16 11:03:46",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.178.246#4848",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1732012": [
        {
            "ioc_value": "212.103.26.10:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2026-01-13 20:03:58",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/212.103.26.10",
            "tags": "AS15557,C2,censys,Havoc,LDCOMNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1731532": [
        {
            "ioc_value": "54.38.94.225:8881",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2026-01-13 08:52:00",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1700820": [
        {
            "ioc_value": "102.117.170.125:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-11 11:00:48",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/102.117.170.125",
            "tags": "AS23889,C2,censys,MauritiusTelecom,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1700191": [
        {
            "ioc_value": "115.190.237.175:35555",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-09 20:02:46",
            "last_seen_utc": "2026-08-09 08:47:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.237.175",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-666666666,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1693365": [
        {
            "ioc_value": "117.72.178.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-08 23:00:12",
            "last_seen_utc": "2026-08-11 03:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.178.246",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1693357": [
        {
            "ioc_value": "172.94.18.103:191",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2026-01-08 22:50:04",
            "last_seen_utc": "2026-08-11 02:44:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1692743": [
        {
            "ioc_value": "38.49.57.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-07 20:02:36",
            "last_seen_utc": "2026-08-11 03:21:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.49.57.15",
            "tags": "AS8796,C2,censys,CobaltStrike,cs-watermark-666666666,FD-298-8796",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691952": [
        {
            "ioc_value": "115.190.233.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2026-01-06 08:02:23",
            "last_seen_utc": "2026-08-11 03:21:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.233.79",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1691605": [
        {
            "ioc_value": "http://213.5.130.122",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:42",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691603": [
        {
            "ioc_value": "http://213.5.130.151",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:41",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691604": [
        {
            "ioc_value": "http://213.5.130.124",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-08-10 18:02:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1691606": [
        {
            "ioc_value": "http://213.5.130.187",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2026-01-05 13:21:40",
            "last_seen_utc": "2026-08-10 18:02:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1689382": [
        {
            "ioc_value": "http://77.110.119.94/ce369e7324834845.php",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.stealc",
            "malware_alias": null,
            "malware_printable": "Stealc",
            "first_seen_utc": "2026-01-02 07:08:13",
            "last_seen_utc": "2026-08-10 18:15:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/bd8c11720b38730d252793461a7a1b26827ae459bf26752a0fcd5e0129fe4ddc/",
            "tags": "c2,stealc",
            "anonymous": 0,
            "reporter": "burger"
        }
    ],
    "1689798": [
        {
            "ioc_value": "157.245.54.75:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2026-01-02 04:03:37",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.245.54.75",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1688739": [
        {
            "ioc_value": "101.34.205.214:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:16",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688738": [
        {
            "ioc_value": "103.171.35.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:15",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688737": [
        {
            "ioc_value": "107.149.192.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:14",
            "last_seen_utc": "2026-08-11 03:21:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688734": [
        {
            "ioc_value": "124.222.218.20:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688735": [
        {
            "ioc_value": "124.221.255.78:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688736": [
        {
            "ioc_value": "123.56.78.220:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:13",
            "last_seen_utc": "2026-08-11 03:21:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688732": [
        {
            "ioc_value": "152.32.202.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688733": [
        {
            "ioc_value": "150.158.119.242:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:12",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688730": [
        {
            "ioc_value": "165.154.244.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-08-11 03:21:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688731": [
        {
            "ioc_value": "156.225.20.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:11",
            "last_seen_utc": "2026-08-11 03:21:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688729": [
        {
            "ioc_value": "182.92.239.94:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:10",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688726": [
        {
            "ioc_value": "39.105.160.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688727": [
        {
            "ioc_value": "38.38.250.99:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688728": [
        {
            "ioc_value": "211.184.175.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:08",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688725": [
        {
            "ioc_value": "45.58.56.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:07",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688723": [
        {
            "ioc_value": "8.130.80.145:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688724": [
        {
            "ioc_value": "8.130.26.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:05",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688721": [
        {
            "ioc_value": "94.74.164.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688722": [
        {
            "ioc_value": "87.251.67.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-30 16:21:03",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1688694": [
        {
            "ioc_value": "16.171.13.191:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-30 16:04:05",
            "last_seen_utc": "2026-08-11 02:43:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/16.171.13.191",
            "tags": "AMAZON-02,AS16509,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1687948": [
        {
            "ioc_value": "222.186.17.103:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-29 08:46:57",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687807": [
        {
            "ioc_value": "163.181.213.114:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-28 18:44:20",
            "last_seen_utc": "2026-08-11 02:43:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1687327": [
        {
            "ioc_value": "37.72.172.58:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-28 07:41:32",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1687170": [
        {
            "ioc_value": "37.72.172.58:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-27 16:02:33",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/37.72.172.58",
            "tags": "AS29802,AsyncRAT,C2,censys,HVC-AS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1686405": [
        {
            "ioc_value": "155.102.62.60:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-25 18:44:15",
            "last_seen_utc": "2026-08-11 02:43:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1686010": [
        {
            "ioc_value": "139.196.223.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-25 07:52:31",
            "last_seen_utc": "2026-08-11 03:21:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.196.223.82",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1685856": [
        {
            "ioc_value": "helpremote.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-24 12:48:51",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685596": [
        {
            "ioc_value": "172.94.18.103:190",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-12-23 22:45:05",
            "last_seen_utc": "2026-08-11 02:44:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1685256": [
        {
            "ioc_value": "115.190.160.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 20:01:06",
            "last_seen_utc": "2026-08-11 03:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.160.206",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1684938": [
        {
            "ioc_value": "8.159.146.72:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 03:00:34",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684936": [
        {
            "ioc_value": "missmovie.lol",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-23 02:54:49",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1684826": [
        {
            "ioc_value": "179.43.186.214:7889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-22 20:01:00",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/179.43.186.214",
            "tags": "AS51852,C2,censys,CobaltStrike,cs-watermark-987654321,PLI-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1684543": [
        {
            "ioc_value": "64.190.113.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-12-22 00:01:20",
            "last_seen_utc": "2026-08-11 02:46:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/64.190.113.161",
            "tags": "AS399629,BLNWX,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1682522": [
        {
            "ioc_value": "155.102.133.61:4506",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-12-18 18:44:36",
            "last_seen_utc": "2026-08-11 02:43:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1681297": [
        {
            "ioc_value": "51.21.199.243:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-17 08:01:42",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.21.199.243",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1680395": [
        {
            "ioc_value": "119.45.160.160:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 06:49:03",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.45.160.160#8889",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1680306": [
        {
            "ioc_value": "43.161.245.186:79",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-16 02:49:55",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1680210": [
        {
            "ioc_value": "39.105.200.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-15 20:00:23",
            "last_seen_utc": "2026-08-09 08:47:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.105.200.188",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1676363": [
        {
            "ioc_value": "67.219.102.244:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-12 02:50:28",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1670887": [
        {
            "ioc_value": "20.157.116.151:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-08 14:58:40",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.157.116.151",
            "tags": "AdaptixC2,AS8069,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1668967": [
        {
            "ioc_value": "180.76.141.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-07 16:01:37",
            "last_seen_utc": "2026-08-11 03:21:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/180.76.141.175",
            "tags": "AS38365,BAIDU,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667182": [
        {
            "ioc_value": "216.238.89.173:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-12-04 00:03:19",
            "last_seen_utc": "2026-08-11 02:45:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/216.238.89.173",
            "tags": "AdaptixC2,AS-VULTR,AS20473,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667122": [
        {
            "ioc_value": "149.28.138.70:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-12-03 20:02:26",
            "last_seen_utc": "2026-08-11 02:43:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.138.70",
            "tags": "AS-VULTR,AS20473,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1667105": [
        {
            "ioc_value": "115.190.161.178:1234",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-03 20:01:15",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.161.178",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-987654321,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1666902": [
        {
            "ioc_value": "122.114.10.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-03 12:31:15",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1666137": [
        {
            "ioc_value": "8.137.149.67:8091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-12-02 12:51:03",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1665523": [
        {
            "ioc_value": "http://213.5.130.104",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665524": [
        {
            "ioc_value": "http://213.5.130.180",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:52",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665525": [
        {
            "ioc_value": "http://213.5.130.106",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:50",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665527": [
        {
            "ioc_value": "http://213.5.130.152",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665528": [
        {
            "ioc_value": "http://213.5.130.107",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665529": [
        {
            "ioc_value": "http://213.5.130.153",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:49",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665530": [
        {
            "ioc_value": "http://213.5.130.100",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665531": [
        {
            "ioc_value": "http://213.5.130.182",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-12-01 14:57:48",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1665454": [
        {
            "ioc_value": "122.114.10.199:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-12-01 12:36:20",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.114.10.199",
            "tags": "AS4837,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1663012": [
        {
            "ioc_value": "47.236.56.15:4445",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-29 12:00:52",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.56.15",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1650889": [
        {
            "ioc_value": "job.itechno.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-26 12:50:54",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1650040": [
        {
            "ioc_value": "156.245.248.173:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-25 10:49:55",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1649977": [
        {
            "ioc_value": "88.192.127.87:4444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.quasar_rat",
            "malware_alias": "CinaRAT,QuasarRAT,Yggdrasil",
            "malware_printable": "Quasar RAT",
            "first_seen_utc": "2025-11-25 08:01:18",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/88.192.127.87",
            "tags": "AS1759,C2,censys,Quasar,RAT,TSF-IP-CORE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1649775": [
        {
            "ioc_value": "http://213.5.130.84",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:37",
            "last_seen_utc": "2026-08-10 18:02:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649776": [
        {
            "ioc_value": "http://213.5.130.96",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649777": [
        {
            "ioc_value": "http://213.5.130.98",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:36",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1649778": [
        {
            "ioc_value": "http://213.5.130.160",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-25 06:01:35",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1647575": [
        {
            "ioc_value": "123.58.64.57:34567",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-21 00:02:05",
            "last_seen_utc": "2026-08-11 02:47:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/123.58.64.57",
            "tags": "AS17623,C2,censys,CNCGROUP-SZ,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1645785": [
        {
            "ioc_value": "47.236.149.142:46832",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-17 23:00:18",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.236.149.142",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1645519": [
        {
            "ioc_value": "http://185.132.133.127",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-08-10 18:02:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1645520": [
        {
            "ioc_value": "http://185.132.133.140",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-17 13:58:09",
            "last_seen_utc": "2026-08-10 18:02:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1641582": [
        {
            "ioc_value": "62.4.0.66:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-15 08:48:18",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,Mythic",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1639703": [
        {
            "ioc_value": "62.60.226.183:483",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.tofsee",
            "malware_alias": "Gheg",
            "malware_printable": "Tofsee",
            "first_seen_utc": "2025-11-13 04:54:17",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,Tofsee",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1639719": [
        {
            "ioc_value": "45.76.190.68:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-13 04:54:12",
            "last_seen_utc": "2026-08-11 02:46:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.76.190.68",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1639434": [
        {
            "ioc_value": "62.4.0.66:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 16:02:00",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.4.0.66",
            "tags": "AS12876,C2,censys,Mythic,Online",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638854": [
        {
            "ioc_value": "54.165.230.182:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-12 04:02:31",
            "last_seen_utc": "2026-08-11 02:46:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.165.230.182",
            "tags": "AMAZON-AES,AS14618,C2,censys,Covenant",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638590": [
        {
            "ioc_value": "45.76.190.68:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-11-11 08:02:54",
            "last_seen_utc": "2026-08-11 02:46:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.76.190.68",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1638274": [
        {
            "ioc_value": "38.242.212.5:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-11-10 18:47:41",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "AdaptixC2,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1638236": [
        {
            "ioc_value": "154.205.145.109:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-11-10 16:02:55",
            "last_seen_utc": "2026-08-11 02:43:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/154.205.145.109",
            "tags": "AS138915,C2,censys,Havoc,KAOPU-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1636099": [
        {
            "ioc_value": "111.228.55.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 23:00:12",
            "last_seen_utc": "2026-08-11 03:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.228.55.96",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1634744": [
        {
            "ioc_value": "165.154.225.239:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-07 02:49:37",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1634389": [
        {
            "ioc_value": "139.196.111.118:8088",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-06 07:26:25",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633501": [
        {
            "ioc_value": "59.110.28.230:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 20:01:04",
            "last_seen_utc": "2026-08-11 03:21:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/59.110.28.230",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633194": [
        {
            "ioc_value": "51.15.8.6:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-11-04 08:00:54",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.8.6",
            "tags": "AS12876,C2,censys,Online,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1633063": [
        {
            "ioc_value": "192.253.227.88:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:22",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1633061": [
        {
            "ioc_value": "167.88.168.76:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-04 02:49:14",
            "last_seen_utc": "2026-08-11 03:21:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1631753": [
        {
            "ioc_value": "117.72.175.125:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.vshell",
            "malware_alias": null,
            "malware_printable": "VShell",
            "first_seen_utc": "2025-11-03 12:08:57",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.nviso.eu/blog",
            "tags": "C2,NVISO,VShell",
            "anonymous": 0,
            "reporter": "0xThiebaut"
        }
    ],
    "1631367": [
        {
            "ioc_value": "117.72.242.9:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 09:03:04",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.242.9",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1631471": [
        {
            "ioc_value": "119.42.148.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-03 07:01:12",
            "last_seen_utc": "2026-08-11 03:21:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/119.42.148.186#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630832": [
        {
            "ioc_value": "157.20.182.18:1337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-11-01 12:36:10",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/157.20.182.18#1337",
            "tags": "asyncrat,c2,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1630704": [
        {
            "ioc_value": "117.72.175.125:8087",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-11-01 12:31:38",
            "last_seen_utc": "2026-08-11 02:46:58",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/117.72.175.125#8087",
            "tags": "c2,cobaltstrike,cs-watermark-391144938,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1629384": [
        {
            "ioc_value": "103.149.93.146:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-30 04:00:42",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.149.93.146",
            "tags": "AS401696,C2,censys,CobaltStrike,COGNETCLOUD,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1628814": [
        {
            "ioc_value": "179.43.186.214:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 09:23:45",
            "last_seen_utc": "2026-08-11 02:47:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1628691": [
        {
            "ioc_value": "8.17.56.128:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-29 02:49:59",
            "last_seen_utc": "2026-08-11 02:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1628076": [
        {
            "ioc_value": "8.137.149.67:8060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 12:28:01",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627925": [
        {
            "ioc_value": "182.254.155.23:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 04:00:27",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/182.254.155.23",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1627719": [
        {
            "ioc_value": "182.16.98.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-28 02:49:21",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1627659": [
        {
            "ioc_value": "182.16.98.84:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-27 20:50:01",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1626705": [
        {
            "ioc_value": "196.251.83.89:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-26 07:39:14",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/196.251.83.89",
            "tags": "AS401120,C2,censys,CHEAPY-HOST",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1626312": [
        {
            "ioc_value": "173.212.216.226:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.chaos",
            "malware_alias": "FakeRyuk,RyukJoke,Yashma",
            "malware_printable": "Chaos",
            "first_seen_utc": "2025-10-25 04:02:07",
            "last_seen_utc": "2026-08-11 02:44:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/173.212.216.226",
            "tags": "AS51167,censys,Chaos,CONTABO,panel",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626300": [
        {
            "ioc_value": "47.121.135.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-25 04:00:11",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.121.135.201",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1626112": [
        {
            "ioc_value": "140.143.194.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-24 16:00:08",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/140.143.194.253",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1625642": [
        {
            "ioc_value": "maelootp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 16:48:58",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625564": [
        {
            "ioc_value": "evil.ritademo.io.vn",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-23 12:50:22",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625107": [
        {
            "ioc_value": "185.72.8.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1625108": [
        {
            "ioc_value": "185.72.8.137:7882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-10-22 18:45:52",
            "last_seen_utc": "2026-08-11 02:44:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1624905": [
        {
            "ioc_value": "116.62.226.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-22 15:43:44",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1624300": [
        {
            "ioc_value": "47.110.67.64:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 20:01:59",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.110.67.64",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1624166": [
        {
            "ioc_value": "http://213.5.130.75",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:24",
            "last_seen_utc": "2026-08-10 18:02:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624167": [
        {
            "ioc_value": "http://213.5.130.10",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:23",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624169": [
        {
            "ioc_value": "http://213.5.130.90",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-08-10 18:02:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1624170": [
        {
            "ioc_value": "http://213.5.130.89",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-21 13:19:22",
            "last_seen_utc": "2026-08-10 18:02:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,REMPROXY",
            "anonymous": 0,
            "reporter": "BlackLotusLabs"
        }
    ],
    "1618876": [
        {
            "ioc_value": "www.salesf0rce.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-21 02:49:37",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1617732": [
        {
            "ioc_value": "157.20.182.18:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-10-19 06:39:17",
            "last_seen_utc": "2026-08-11 02:43:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.20.182.18",
            "tags": "AS152485,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1617285": [
        {
            "ioc_value": "5.152.16.189:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-10-17 12:02:17",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.152.16.189",
            "tags": "AS35805,C2,censys,Netsupport,RAT,SILKNET-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1617002": [
        {
            "ioc_value": "3.143.55.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-17 08:02:43",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.143.55.137",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1616729": [
        {
            "ioc_value": "47.129.2.130:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:50:54",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1616728": [
        {
            "ioc_value": "ns1.gygiuh.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-16 22:49:04",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1615761": [
        {
            "ioc_value": "89.58.30.49:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-10-14 20:02:48",
            "last_seen_utc": "2026-08-11 02:46:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.58.30.49",
            "tags": "AS197540,C2,censys,Covenant,NETCUP-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1614712": [
        {
            "ioc_value": "5.101.82.60:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-10-14 08:01:33",
            "last_seen_utc": "2026-08-11 02:46:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/5.101.82.60",
            "tags": "AS-GLOBALTELEHOST,AS63023,C2,censys,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1610023": [
        {
            "ioc_value": "118.25.16.250:801",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-10-09 09:06:15",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1608986": [
        {
            "ioc_value": "45.138.16.162:4321",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-10-07 20:02:30",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.138.16.162",
            "tags": "AdaptixC2,AS210558,C2,censys,SERVICES-1337-GMBH",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1604523": [
        {
            "ioc_value": "18.219.51.236:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-30 04:00:23",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.219.51.236",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1604499": [
        {
            "ioc_value": "149.50.135.215:49152",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-30 00:02:15",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.50.135.215",
            "tags": "AdaptixC2,AS27823,C2,censys,Dattatec.com",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1603281": [
        {
            "ioc_value": "154.92.15.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-28 15:48:32",
            "last_seen_utc": "2026-08-11 03:21:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "c2,censys,cobalt strike",
            "anonymous": 0,
            "reporter": "sojubear"
        }
    ],
    "1602679": [
        {
            "ioc_value": "43.166.246.26:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-27 05:44:59",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-426352781",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1601556": [
        {
            "ioc_value": "115.120.245.134:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 20:00:39",
            "last_seen_utc": "2026-08-11 03:21:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.120.245.134",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-987654321,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1601359": [
        {
            "ioc_value": "196.251.69.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-25 12:51:01",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1599651": [
        {
            "ioc_value": "47.113.186.138:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-24 20:00:10",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.113.186.138",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599442": [
        {
            "ioc_value": "43.162.114.240:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-24 08:02:13",
            "last_seen_utc": "2026-08-11 02:45:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.240",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599090": [
        {
            "ioc_value": "46.21.153.148:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-23 20:01:59",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.21.153.148",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1599091": [
        {
            "ioc_value": "46.21.153.146:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-23 20:01:59",
            "last_seen_utc": "2026-08-11 02:46:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.21.153.146",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1598336": [
        {
            "ioc_value": "43.139.170.200:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-23 06:06:58",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1598300": [
        {
            "ioc_value": "43.162.114.107:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-23 04:00:59",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.114.107",
            "tags": "AS132203,censys,EvilGinx,Phishing",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1598102": [
        {
            "ioc_value": "159.75.211.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:51:05",
            "last_seen_utc": "2026-08-11 02:47:08",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1598100": [
        {
            "ioc_value": "cstest.mucfc.store",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 14:49:30",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597898": [
        {
            "ioc_value": "ns2.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:38",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1597894": [
        {
            "ioc_value": "ns1.cryptwechat.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-22 08:49:35",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1596535": [
        {
            "ioc_value": "43.162.108.133:4000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-21 16:01:22",
            "last_seen_utc": "2026-08-11 02:45:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.162.108.133",
            "tags": "AS132203,censys,EvilGinx,panel,Phishing,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1589068": [
        {
            "ioc_value": "18.167.174.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-09-13 04:01:58",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.167.174.198",
            "tags": "AMAZON-02,AS16509,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588789": [
        {
            "ioc_value": "144.208.127.243:50375",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-09-13 00:02:05",
            "last_seen_utc": "2026-08-11 02:43:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/144.208.127.243",
            "tags": "AS395092,C2,censys,SHOCK-1,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588133": [
        {
            "ioc_value": "195.178.110.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:36",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.178.110.135",
            "tags": "AS48090,C2,censys,CobaltStrike,cs-watermark-426352781,DMZHOST",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1588128": [
        {
            "ioc_value": "150.158.170.241:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 20:01:30",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.158.170.241",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1587773": [
        {
            "ioc_value": "106.12.111.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-11 06:43:14",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1587441": [
        {
            "ioc_value": "101.32.109.112:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-10 20:01:24",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.32.109.112",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1583496": [
        {
            "ioc_value": "43.225.157.146:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-09-07 20:02:05",
            "last_seen_utc": "2026-08-11 02:45:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.225.157.146",
            "tags": "AS142403,AsyncRAT,C2,censys,RAT,YISUCLOUDLTD-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1582910": [
        {
            "ioc_value": "8.138.222.215:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-06 20:01:18",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.138.222.215",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1581557": [
        {
            "ioc_value": "8.148.194.157:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-04 07:40:17",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.148.194.157#443",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580723": [
        {
            "ioc_value": "47.236.159.248:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:52:55",
            "last_seen_utc": "2026-08-11 02:47:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580721": [
        {
            "ioc_value": "ns2.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:45",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580720": [
        {
            "ioc_value": "ns1.microoosoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 18:50:42",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1580257": [
        {
            "ioc_value": "47.121.137.8:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-09-02 05:43:42",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.121.137.8#80",
            "tags": "c2,cobaltstrike,cs-watermark-666666666,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1580237": [
        {
            "ioc_value": "47.99.196.178:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-09-02 04:01:38",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.99.196.178",
            "tags": "AdaptixC2,ALIBABA-CN-NET,AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578921": [
        {
            "ioc_value": "109.205.181.248:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-09-01 00:01:11",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1578899": [
        {
            "ioc_value": "103.73.66.43:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-31 20:50:07",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1578379": [
        {
            "ioc_value": "109.205.181.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-31 04:00:27",
            "last_seen_utc": "2026-08-11 02:43:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/109.205.181.248",
            "tags": "AS51167,C2,censys,CONTABO,Mythic",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1577783": [
        {
            "ioc_value": "43.199.78.142:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:50:45",
            "last_seen_utc": "2026-08-11 02:47:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577775": [
        {
            "ioc_value": "n1.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577776": [
        {
            "ioc_value": "n2.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577777": [
        {
            "ioc_value": "n3.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:03",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1577774": [
        {
            "ioc_value": "lab.google-analytcis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-29 22:49:01",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1576432": [
        {
            "ioc_value": "46.246.82.10:2003",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-08-28 20:01:21",
            "last_seen_utc": "2026-08-11 02:46:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/46.246.82.10",
            "tags": "AS42708,C2,censys,DcRAT,GLESYS,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1574099": [
        {
            "ioc_value": "89.216.98.17:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-08-25 08:14:17",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/89.216.98.17#3085",
            "tags": "c2,netsupport,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1573705": [
        {
            "ioc_value": "43.163.112.217:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-25 00:00:27",
            "last_seen_utc": "2026-08-11 03:21:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/43.163.112.217",
            "tags": "AS132203,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1573112": [
        {
            "ioc_value": "3.24.114.211:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-23 16:00:59",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.24.114.211",
            "tags": "AMAZON-02,AS16509,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1571607": [
        {
            "ioc_value": "178.16.55.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-20 08:02:12",
            "last_seen_utc": "2026-08-11 03:21:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/178.16.55.53",
            "tags": "C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570775": [
        {
            "ioc_value": "116.203.31.207:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-18 20:01:59",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.203.31.207",
            "tags": "AS24940,C2,censys,CobaltStrike,cs-watermark-987654321,HETZNER-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1570558": [
        {
            "ioc_value": "150.187.25.242:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-17 20:01:54",
            "last_seen_utc": "2026-08-11 02:47:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.187.25.242",
            "tags": "AS20312,C2,censys,CobaltStrike,cs-watermark-987654321,Fundacion",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569825": [
        {
            "ioc_value": "8.138.167.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 15:22:26",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/8.138.167.123#443",
            "tags": "c2,cobaltstrike,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1569780": [
        {
            "ioc_value": "119.29.231.118:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-16 08:01:47",
            "last_seen_utc": "2026-08-11 03:21:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.29.231.118",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1569167": [
        {
            "ioc_value": "116.198.233.179:6666",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 21:57:45",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/116.198.233.179#6666",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1569004": [
        {
            "ioc_value": "8ve3qsgxk7rs6.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 12:49:06",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1568713": [
        {
            "ioc_value": "117.72.184.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-15 06:21:34",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.184.172",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1568192": [
        {
            "ioc_value": "115.190.138.41:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-13 16:01:30",
            "last_seen_utc": "2026-08-11 02:46:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/115.190.138.41",
            "tags": "AS137718,C2,censys,CobaltStrike,cs-watermark-391144938,VOLCANO-ENGINE",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567756": [
        {
            "ioc_value": "116.198.233.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 20:01:25",
            "last_seen_utc": "2026-08-11 03:21:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/116.198.233.179",
            "tags": "AS137699,C2,censys,CHINATELECOM-JIANGSU-SUQIAN-IDC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567668": [
        {
            "ioc_value": "62.117.98.115:8001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-12 12:01:59",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.117.98.115",
            "tags": "AS8732,C2,censys,COMCOR-AS,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567648": [
        {
            "ioc_value": "107.174.115.43:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-12 10:50:19",
            "last_seen_utc": "2026-08-11 02:46:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1567316": [
        {
            "ioc_value": "209.250.227.127:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2025-08-11 20:01:43",
            "last_seen_utc": "2026-08-11 02:44:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/209.250.227.127",
            "tags": "AS-VULTR,AS20473,C2,censys,Pupy,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1567234": [
        {
            "ioc_value": "45.204.216.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-11 08:01:15",
            "last_seen_utc": "2026-08-11 03:21:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.204.216.24",
            "tags": "AS62468,C2,censys,CobaltStrike,cs-watermark-987654321,HKCLOUDX",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1565164": [
        {
            "ioc_value": "8.219.76.168:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-06 12:54:26",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564496": [
        {
            "ioc_value": "47.105.36.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-08-05 08:53:36",
            "last_seen_utc": "2026-08-11 03:21:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564345": [
        {
            "ioc_value": "185.233.166.124:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1564346": [
        {
            "ioc_value": "185.233.166.124:9702",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-08-04 20:45:44",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1563211": [
        {
            "ioc_value": "89.197.168.150:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-08-01 20:01:06",
            "last_seen_utc": "2026-08-11 02:46:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/89.197.168.150",
            "tags": "AS47474,C2,censys,Mythic,VIRTUAL1",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1562698": [
        {
            "ioc_value": "68.133.1.34:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.xenorat",
            "malware_alias": null,
            "malware_printable": "XenoRAT",
            "first_seen_utc": "2025-07-31 01:20:10",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "XenoRAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1562605": [
        {
            "ioc_value": "172.233.97.159:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-30 20:01:06",
            "last_seen_utc": "2026-08-11 02:44:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/172.233.97.159",
            "tags": "AKAMAI-LINODE-AP,AS63949,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1561533": [
        {
            "ioc_value": "217.154.212.25:3000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-28 05:29:47",
            "last_seen_utc": "2026-08-11 02:45:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1561181": [
        {
            "ioc_value": "117.72.181.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-27 16:00:55",
            "last_seen_utc": "2026-08-11 03:21:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.181.104",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1560617": [
        {
            "ioc_value": "47.236.130.154:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-25 10:51:18",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1559594": [
        {
            "ioc_value": "158.255.213.22:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-07-22 20:44:22",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1559595": [
        {
            "ioc_value": "158.255.213.22:63421",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-07-22 20:44:22",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558329": [
        {
            "ioc_value": "103.125.248.109:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-19 12:49:30",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558066": [
        {
            "ioc_value": "193.112.84.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-18 12:51:20",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1558027": [
        {
            "ioc_value": "206.189.227.148:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-07-18 08:01:12",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.189.227.148",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1557619": [
        {
            "ioc_value": "ns3.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:04",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557618": [
        {
            "ioc_value": "ns2.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:03",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1557617": [
        {
            "ioc_value": "ns1.nsebseshop.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-16 22:49:02",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1556749": [
        {
            "ioc_value": "118.31.18.77:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-14 20:45:17",
            "last_seen_utc": "2026-08-11 02:47:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.31.18.77",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1554340": [
        {
            "ioc_value": "88.129.147.201:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-07-07 20:54:20",
            "last_seen_utc": "2026-08-11 02:46:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1554064": [
        {
            "ioc_value": "8.152.99.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-07-06 20:00:32",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.152.99.85",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1552208": [
        {
            "ioc_value": "146.70.87.96:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-02 04:02:12",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.87.96",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1551843": [
        {
            "ioc_value": "38.132.122.141:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-07-01 04:02:16",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.132.122.141",
            "tags": "AdaptixC2,AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1550785": [
        {
            "ioc_value": "43.139.50.42:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-28 10:56:20",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1549030": [
        {
            "ioc_value": "156.227.233.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-25 04:00:19",
            "last_seen_utc": "2026-08-11 03:21:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/156.227.233.153",
            "tags": "AS138152,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1548104": [
        {
            "ioc_value": "158.158.0.196:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-20 20:02:50",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1547925": [
        {
            "ioc_value": "82.156.156.160:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-20 06:01:32",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1546420": [
        {
            "ioc_value": "158.158.0.196:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-06-19 00:02:44",
            "last_seen_utc": "2026-08-11 02:43:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/158.158.0.196",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1546246": [
        {
            "ioc_value": "191.93.118.254:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-06-18 08:02:37",
            "last_seen_utc": "2026-08-11 02:44:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/9265a6e0b26a240f1f8bffddf3b36d0e533919d0c894bd66839a90e351961464/",
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545615": [
        {
            "ioc_value": "8.147.128.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-17 03:12:25",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1545348": [
        {
            "ioc_value": "8.137.149.67:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-16 12:01:46",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.137.149.67",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544612": [
        {
            "ioc_value": "47.109.48.57:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-13 20:01:30",
            "last_seen_utc": "2026-08-11 03:21:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.48.57",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1544039": [
        {
            "ioc_value": "39.104.78.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-12 08:56:19",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.104.78.25",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1543390": [
        {
            "ioc_value": "8.155.0.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-10 16:01:13",
            "last_seen_utc": "2026-08-11 03:21:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.155.0.238",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542804": [
        {
            "ioc_value": "23.227.203.191:43211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.adaptix_c2",
            "malware_alias": null,
            "malware_printable": "AdaptixC2",
            "first_seen_utc": "2025-06-08 21:18:37",
            "last_seen_utc": "2026-08-11 02:45:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.227.203.191",
            "tags": "AdaptixC2,AS29802,C2,censys,HVC-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1542759": [
        {
            "ioc_value": "119.45.29.172:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-08 20:01:01",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/119.45.29.172",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1541652": [
        {
            "ioc_value": "68.64.176.42:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-06 16:00:50",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.64.176.42",
            "tags": "AS139659,C2,censys,CobaltStrike,cs-watermark-391144938,LUCID-AS-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1538881": [
        {
            "ioc_value": "193.239.85.15:2083",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-06-02 12:01:04",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.239.85.15",
            "tags": "AS9009,C2,censys,Havoc,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1538799": [
        {
            "ioc_value": "47.109.198.8:6000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-06-02 05:47:28",
            "last_seen_utc": "2026-08-11 02:47:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/47.109.198.8#6000",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1538358": [
        {
            "ioc_value": "54.38.94.225:8885",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-06-01 08:52:56",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1537676": [
        {
            "ioc_value": "101.43.91.156:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:39",
            "last_seen_utc": "2026-08-11 03:21:32",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1537678": [
        {
            "ioc_value": "59.110.7.32:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-31 07:45:38",
            "last_seen_utc": "2026-08-11 03:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1536850": [
        {
            "ioc_value": "99.112.198.249:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-05-30 08:53:21",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536831": [
        {
            "ioc_value": "129.28.85.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 08:00:11",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/129.28.85.210",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-666666666,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1536730": [
        {
            "ioc_value": "111.229.4.108:2096",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-30 02:55:17",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1536683": [
        {
            "ioc_value": "161.35.176.231:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-05-29 22:26:34",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.176.231",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533613": [
        {
            "ioc_value": "221.132.29.137:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-24 20:01:31",
            "last_seen_utc": "2026-08-11 02:45:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/221.132.29.137",
            "tags": "AS45899,C2,censys,Mythic,VNPT-AS-VN",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1533071": [
        {
            "ioc_value": "1.15.174.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-24 11:13:44",
            "last_seen_utc": "2026-08-11 03:21:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1532332": [
        {
            "ioc_value": "8.140.239.162:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-23 05:34:51",
            "last_seen_utc": "2026-08-11 03:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1531654": [
        {
            "ioc_value": "122.10.49.137:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 16:00:35",
            "last_seen_utc": "2026-08-11 02:47:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.10.49.137",
            "tags": "AS134548,C2,censys,CobaltStrike,cs-watermark-1234567890,DXTL-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1527752": [
        {
            "ioc_value": "117.72.206.39:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 08:00:35",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.206.39",
            "tags": "AS141679,C2,censys,CHINATELECOM-IDC-BTHBD-AP,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1527457": [
        {
            "ioc_value": "122.10.25.26:808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-21 00:00:32",
            "last_seen_utc": "2026-08-11 02:47:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/122.10.25.26",
            "tags": "AS134548,C2,censys,CobaltStrike,cs-watermark-1234567890,DXTL-HK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1526357": [
        {
            "ioc_value": "106.54.61.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-20 06:37:42",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1525250": [
        {
            "ioc_value": "124.223.114.203:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-18 15:34:22",
            "last_seen_utc": "2026-08-11 03:21:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://intelinsights.substack.com/p/from-939-to-85-hunting-cobalt-strike",
            "tags": "censys,cobaltstrike",
            "anonymous": 0,
            "reporter": "orlof_v"
        }
    ],
    "1524773": [
        {
            "ioc_value": "167.99.51.2:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 14:42:08",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.99.51.2#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1524641": [
        {
            "ioc_value": "167.99.51.2:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-05-17 08:00:32",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.99.51.2",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1524319": [
        {
            "ioc_value": "101.35.109.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-17 06:26:23",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/101.35.109.246#443",
            "tags": "c2,cobaltstrike,cs-watermark-987654321,shodan",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1523466": [
        {
            "ioc_value": "103.171.35.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:57",
            "last_seen_utc": "2026-08-11 03:21:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523462": [
        {
            "ioc_value": "60.204.169.16:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:14:47",
            "last_seen_utc": "2026-08-11 03:21:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523434": [
        {
            "ioc_value": "179.43.186.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-15 21:13:56",
            "last_seen_utc": "2026-08-11 03:21:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://x.com/abodovic1",
            "tags": "c2,censys,cobalt_strike",
            "anonymous": 0,
            "reporter": "Abodovic"
        }
    ],
    "1523280": [
        {
            "ioc_value": "45.133.180.138:6432",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2025-05-15 06:10:52",
            "last_seen_utc": "2026-08-11 02:45:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/b6185d4054c5a08141db4c3fb5e43369ea21af5892d8ba47628e23f37f79250d/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520343": [
        {
            "ioc_value": "38.54.112.234:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:58:42",
            "last_seen_utc": "2026-08-11 02:47:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1520342": [
        {
            "ioc_value": "asusupdateserver.asuscomm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-12 20:55:40",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1519438": [
        {
            "ioc_value": "47.109.190.151:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-11 06:11:06",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.109.190.151",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1519451": [
        {
            "ioc_value": "https://lofiramegi.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:18",
            "last_seen_utc": "2026-08-11 03:18:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1519450": [
        {
            "ioc_value": "https://topguningit.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-05-11 05:00:17",
            "last_seen_utc": "2026-08-11 03:26:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1518529": [
        {
            "ioc_value": "47.108.140.10:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-05-09 05:36:03",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.108.140.10",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1518023": [
        {
            "ioc_value": "106.52.207.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-05-07 13:00:19",
            "last_seen_utc": "2026-08-11 02:46:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513590": [
        {
            "ioc_value": "54.38.94.225:8882",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-04-29 08:53:29",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1513585": [
        {
            "ioc_value": "107.143.144.154:8080",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-04-29 08:43:42",
            "last_seen_utc": "2026-08-11 02:43:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1511917": [
        {
            "ioc_value": "181.206.158.190:1000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.dcrat",
            "malware_alias": "DarkCrystal RAT",
            "malware_printable": "DCRat",
            "first_seen_utc": "2025-04-26 20:01:51",
            "last_seen_utc": "2026-08-11 02:44:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/181.206.158.190",
            "tags": "AS27831,C2,censys,Colombia,DcRAT,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1509966": [
        {
            "ioc_value": "167.71.13.103:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-22 12:21:47",
            "last_seen_utc": "2026-08-11 02:43:56",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://www.shodan.io/host/167.71.13.103#31337",
            "tags": "c2,shodan,sliver",
            "anonymous": 0,
            "reporter": "juroots"
        }
    ],
    "1493521": [
        {
            "ioc_value": "77.73.129.82:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-04-18 08:02:32",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.73.129.82",
            "tags": "AS201814,C2,censys,MEVSPACE,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492480": [
        {
            "ioc_value": "113.45.253.80:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-16 16:01:35",
            "last_seen_utc": "2026-08-11 02:46:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.45.253.80",
            "tags": "AS55990,C2,censys,CobaltStrike,cs-watermark-666666666,HWCSNET",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1492012": [
        {
            "ioc_value": "47.83.134.97:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-04-15 16:02:30",
            "last_seen_utc": "2026-08-11 02:46:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.83.134.97",
            "tags": "ALIBABA-CN-NET,AS45102,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1491748": [
        {
            "ioc_value": "193.142.146.70:56004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-04-15 04:01:37",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1486437": [
        {
            "ioc_value": "167.71.13.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2025-04-10 05:55:49",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/167.71.13.103",
            "tags": "AS14061,C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1463173": [
        {
            "ioc_value": "38.46.218.36:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:14",
            "last_seen_utc": "2026-08-11 01:50:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463174": [
        {
            "ioc_value": "38.46.218.38:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:13",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463176": [
        {
            "ioc_value": "38.46.218.39:9999",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.vo1d",
            "malware_alias": null,
            "malware_printable": "vo1d",
            "first_seen_utc": "2025-04-02 10:08:12",
            "last_seen_utc": "2026-08-11 02:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Vo1d",
            "anonymous": 0,
            "reporter": "Bitsight"
        }
    ],
    "1463152": [
        {
            "ioc_value": "200.107.126.227:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-04-02 08:01:26",
            "last_seen_utc": "2026-08-11 02:44:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/200.107.126.227",
            "tags": "AS14754,C2,censys,Netsupport,RAT,TELECOMUNICACIONES",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1462468": [
        {
            "ioc_value": "43.143.229.126:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-04-01 10:24:30",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1461919": [
        {
            "ioc_value": "8.140.239.162:81",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-31 06:14:47",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.239.162",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1459722": [
        {
            "ioc_value": "193.142.146.70:2404",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.remcos",
            "malware_alias": "RemcosRAT,Remvio,Socmer",
            "malware_printable": "Remcos",
            "first_seen_utc": "2025-03-28 04:00:35",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.142.146.70",
            "tags": "AS213438,C2,censys,COLOCATEL-INC,RAT,Remcos",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1458716": [
        {
            "ioc_value": "ehchq7m7rpvdr.cfc-execute.bj.baidubce.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-25 22:53:24",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1457513": [
        {
            "ioc_value": "103.142.147.17:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-24 06:29:33",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.142.147.17",
            "tags": "AS135581,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1454148": [
        {
            "ioc_value": "103.142.147.18:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1454149": [
        {
            "ioc_value": "103.142.147.19:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-22 20:43:16",
            "last_seen_utc": "2026-08-11 02:43:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1452404": [
        {
            "ioc_value": "47.116.208.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-20 12:01:27",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.116.208.81",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-666666666",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1446559": [
        {
            "ioc_value": "www.dyshop.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-12 02:47:28",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1444156": [
        {
            "ioc_value": "47.100.16.83:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-09 04:00:17",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.100.16.83",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1441526": [
        {
            "ioc_value": "68.219.250.95:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-05 16:01:26",
            "last_seen_utc": "2026-08-11 02:46:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/68.219.250.95",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439776": [
        {
            "ioc_value": "150.5.174.231:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-03-02 20:01:03",
            "last_seen_utc": "2026-08-11 02:43:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/150.5.174.231",
            "tags": "AS150436,BYTEPLUS-AS-AP,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1439368": [
        {
            "ioc_value": "54.38.94.225:8887",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-03-02 08:46:23",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439168": [
        {
            "ioc_value": "47.129.171.26:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:47:46",
            "last_seen_utc": "2026-08-11 02:47:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439166": [
        {
            "ioc_value": "ns.1.3.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-08-11 02:46:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1439167": [
        {
            "ioc_value": "ns.1.4.0o0.foo",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-03-01 20:46:51",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1414853": [
        {
            "ioc_value": "54.95.208.190:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2025-02-19 04:01:34",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.95.208.190",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1411885": [
        {
            "ioc_value": "192.52.167.140:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2025-02-14 00:01:07",
            "last_seen_utc": "2026-08-11 02:44:26",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/192.52.167.140",
            "tags": "AS199959,C2,censys,CROWNCLOUD,Netsupport,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1409420": [
        {
            "ioc_value": "103.215.81.156:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-02-10 20:43:10",
            "last_seen_utc": "2026-08-11 02:43:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1405307": [
        {
            "ioc_value": "https://apworsindos.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-08-11 03:24:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1405308": [
        {
            "ioc_value": "https://reminasolirol.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-06 13:54:51",
            "last_seen_utc": "2026-08-11 03:16:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1404178": [
        {
            "ioc_value": "20.74.209.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-05 22:51:06",
            "last_seen_utc": "2026-08-11 03:21:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402480": [
        {
            "ioc_value": "service-rchqbzvz-1301033415.sh.tencentapigw.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-02-02 12:49:35",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1402273": [
        {
            "ioc_value": "https://vivaforevew.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-01 20:47:38",
            "last_seen_utc": "2026-08-11 03:21:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1402274": [
        {
            "ioc_value": "https://wersogkiwgow.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2025-02-01 20:47:38",
            "last_seen_utc": "2026-08-11 03:11:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Rony"
        }
    ],
    "1398820": [
        {
            "ioc_value": "162.252.173.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 13:44:30",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1398810": [
        {
            "ioc_value": "162.252.173.12:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-31 12:01:38",
            "last_seen_utc": "2026-08-11 02:43:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/162.252.173.12",
            "tags": "AS9009,backdoor,C2,censys,M247,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1398657": [
        {
            "ioc_value": "8.134.108.73:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2025-01-31 07:01:30",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.134.108.73",
            "tags": "AS37963,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1396136": [
        {
            "ioc_value": "38.146.28.93:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:47:19",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396135": [
        {
            "ioc_value": "185.33.86.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:45:48",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1396130": [
        {
            "ioc_value": "38.146.28.93:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 08:01:38",
            "last_seen_utc": "2026-08-11 02:45:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.146.28.93",
            "tags": "AS174,backdoor,C2,censys,COGENT-174,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1396102": [
        {
            "ioc_value": "185.33.86.15:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-30 04:01:31",
            "last_seen_utc": "2026-08-11 02:44:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.33.86.15",
            "tags": "AS202015,backdoor,C2,censys,HZ-US-AS,Ransomhub",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1394408": [
        {
            "ioc_value": "54.38.94.225:8883",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-26 08:46:00",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1394158": [
        {
            "ioc_value": "54.38.94.225:8880",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-25 20:47:04",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1391610": [
        {
            "ioc_value": "45.82.85.50:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-22 17:46:05",
            "last_seen_utc": "2026-08-11 02:46:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1386236": [
        {
            "ioc_value": "https://135.181.31.18",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2025-01-18 16:10:00",
            "last_seen_utc": "2026-08-11 03:10:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Gi7w0rm"
        }
    ],
    "1384933": [
        {
            "ioc_value": "38.180.81.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384934": [
        {
            "ioc_value": "38.180.81.153:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:15:21",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384921": [
        {
            "ioc_value": "167.99.139.231:8004",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.eye_pyramid",
            "malware_alias": null,
            "malware_printable": "Eye Pyramid",
            "first_seen_utc": "2025-01-17 09:14:13",
            "last_seen_utc": "2026-08-11 02:43:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,EyePyramid",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384912": [
        {
            "ioc_value": "185.174.101.240:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384913": [
        {
            "ioc_value": "185.174.101.240:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384914": [
        {
            "ioc_value": "185.174.101.69:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-11 02:44:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384915": [
        {
            "ioc_value": "185.174.101.69:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:13:19",
            "last_seen_utc": "2026-08-11 02:44:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384908": [
        {
            "ioc_value": "108.181.115.171:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384909": [
        {
            "ioc_value": "108.181.115.171:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384910": [
        {
            "ioc_value": "108.181.182.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384911": [
        {
            "ioc_value": "108.181.182.143:8000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.ransomhub",
            "malware_alias": null,
            "malware_printable": "RansomHub",
            "first_seen_utc": "2025-01-17 09:12:27",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "drb-ra,RansomHub",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384790": [
        {
            "ioc_value": "at1.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384791": [
        {
            "ioc_value": "at2.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1384792": [
        {
            "ioc_value": "at3.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-17 07:45:55",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1381420": [
        {
            "ioc_value": "77.238.236.123:18300",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:55:47",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1381067": [
        {
            "ioc_value": "112.5.58.181:7001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos_c2",
            "malware_alias": null,
            "malware_printable": "DeimosC2",
            "first_seen_utc": "2025-01-10 13:43:51",
            "last_seen_utc": "2026-08-11 02:43:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "Deimos,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380875": [
        {
            "ioc_value": "update.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380878": [
        {
            "ioc_value": "upgrade.mloadspring.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:38",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380837": [
        {
            "ioc_value": "ns3.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380841": [
        {
            "ioc_value": "ns3.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:30",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380833": [
        {
            "ioc_value": "ns2.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:29",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380818": [
        {
            "ioc_value": "ns2.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:27",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380815": [
        {
            "ioc_value": "ns2.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:26",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380811": [
        {
            "ioc_value": "ns1.translategoos.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:25",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380783": [
        {
            "ioc_value": "ns1.akawowfast.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380787": [
        {
            "ioc_value": "ns1.cmbchina.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 09:14:20",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380635": [
        {
            "ioc_value": "8.219.78.159:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:57",
            "last_seen_utc": "2026-08-11 02:47:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380629": [
        {
            "ioc_value": "70.34.196.238:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:43",
            "last_seen_utc": "2026-08-11 02:47:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380607": [
        {
            "ioc_value": "47.98.134.252:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:18:28",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380533": [
        {
            "ioc_value": "207.148.68.118:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:17:20",
            "last_seen_utc": "2026-08-11 02:47:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380446": [
        {
            "ioc_value": "139.180.189.95:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:16:21",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380421": [
        {
            "ioc_value": "118.25.91.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:44",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1380420": [
        {
            "ioc_value": "117.72.39.83:43872",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-10 08:15:43",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,drb-ra",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1377524": [
        {
            "ioc_value": "8.140.239.162:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2025-01-03 08:01:15",
            "last_seen_utc": "2026-08-11 02:47:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1376919": [
        {
            "ioc_value": "86.124.168.255:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2025-01-01 04:03:19",
            "last_seen_utc": "2026-08-11 02:46:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.124.168.255",
            "tags": "AS8708,c2,censys,RCS-RDS,SocGholish",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359401": [
        {
            "ioc_value": "8.153.97.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-24 08:00:43",
            "last_seen_utc": "2026-08-11 03:21:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.153.97.202",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359309": [
        {
            "ioc_value": "91.199.154.103:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-12-24 04:01:34",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "AS62212,C2,censys,Sliver",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1359295": [
        {
            "ioc_value": "54.95.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-12-24 00:02:17",
            "last_seen_utc": "2026-08-11 02:46:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/54.95.208.190",
            "tags": "AMAZON-02,AS16509,C2,censys,Havoc",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1358842": [
        {
            "ioc_value": "149.28.61.158:8773",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-20 16:01:53",
            "last_seen_utc": "2026-08-11 02:43:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.61.158",
            "tags": "AS-VULTR,AS20473,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1357389": [
        {
            "ioc_value": "45.56.69.210:3333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-16 16:01:41",
            "last_seen_utc": "2026-08-11 02:45:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/45.56.69.210",
            "tags": "AKAMAI-LINODE-AP,AS63949,censys,EvilGoPhish,panel,Phishing",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1356002": [
        {
            "ioc_value": "113.44.90.0:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-12-12 06:21:40",
            "last_seen_utc": "2026-08-11 02:43:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/113.44.90.0",
            "tags": "AS55990,censys,Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1352876": [
        {
            "ioc_value": "139.196.126.161:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-06 07:36:52",
            "last_seen_utc": "2026-08-11 03:21:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1350210": [
        {
            "ioc_value": "117.72.39.83:4433",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-02 21:01:15",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1349957": [
        {
            "ioc_value": "117.72.39.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-12-01 07:43:42",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1349567": [
        {
            "ioc_value": "216.118.101.24:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:19",
            "last_seen_utc": "2026-08-11 02:45:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349531": [
        {
            "ioc_value": "216.118.101.132:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:11",
            "last_seen_utc": "2026-08-11 02:44:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349510": [
        {
            "ioc_value": "216.118.101.199:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:08",
            "last_seen_utc": "2026-08-11 02:45:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349492": [
        {
            "ioc_value": "216.118.101.216:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:06:04",
            "last_seen_utc": "2026-08-11 02:45:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1349438": [
        {
            "ioc_value": "216.118.101.54:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-30 20:05:51",
            "last_seen_utc": "2026-08-11 02:45:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,panel,Viper",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348902": [
        {
            "ioc_value": "216.118.101.108:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-11-29 13:56:30",
            "last_seen_utc": "2026-08-11 02:44:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Viper",
            "anonymous": 0,
            "reporter": "dyingbreeds_"
        }
    ],
    "1348295": [
        {
            "ioc_value": "47.90.142.15:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:54",
            "last_seen_utc": "2026-08-11 03:21:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1348026": [
        {
            "ioc_value": "8.137.114.210:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-27 19:47:07",
            "last_seen_utc": "2026-08-11 03:21:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "censys,CobaltStrike",
            "anonymous": 0,
            "reporter": "NDA0E"
        }
    ],
    "1346058": [
        {
            "ioc_value": "servicioremotoempresas.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-11-19 18:00:05",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1340201": [
        {
            "ioc_value": "146.70.158.198:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-10-30 17:53:55",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://github.com/TheRavenFile/Daily-Hunt/blob/main/Sliver%20C2",
            "tags": "c2,sliver,sliverc2",
            "anonymous": 0,
            "reporter": "TheRavenFile"
        }
    ],
    "1338675": [
        {
            "ioc_value": "https://stripplasst.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:41",
            "last_seen_utc": "2026-08-11 03:12:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338673": [
        {
            "ioc_value": "https://skinnyjeanso.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:39",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1338670": [
        {
            "ioc_value": "https://coolarition.com/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-10-22 13:56:34",
            "last_seen_utc": "2026-08-11 03:20:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.vmray.com/latrodectus-a-year-in-the-making/",
            "tags": "c2,latrodectus,vmray",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1332328": [
        {
            "ioc_value": "195.100.198.220:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-10-01 16:02:09",
            "last_seen_utc": "2026-08-11 02:44:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/195.100.198.220",
            "tags": "AS5400,BT,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1329042": [
        {
            "ioc_value": "118.25.148.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-09-25 08:00:47",
            "last_seen_utc": "2026-08-11 03:21:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.148.25",
            "tags": "AS45090,C2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1326604": [
        {
            "ioc_value": "206.210.123.104:8889",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-09-20 08:01:06",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "AS33130,C2,censys,IASL,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1326051": [
        {
            "ioc_value": "https://isomicrotich.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:51",
            "last_seen_utc": "2026-08-11 03:24:21",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1326052": [
        {
            "ioc_value": "https://rilomenifis.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.latrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-09-19 14:07:50",
            "last_seen_utc": "2026-08-11 03:15:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "1.7,Alpha",
            "anonymous": 0,
            "reporter": "spamhaus"
        }
    ],
    "1317376": [
        {
            "ioc_value": "https://pikchestop.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-08-11 03:10:34",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317377": [
        {
            "ioc_value": "https://indepahote.com/test/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.lactrodectus",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Latrodectus",
            "first_seen_utc": "2024-08-30 07:05:10",
            "last_seen_utc": "2026-08-11 03:20:37",
            "confidence_level": 49,
            "is_compromised": false,
            "reference": "https://www.netskope.com/jp/blog/latrodectus-rapid-evolution-continues-with-latest-new-payload-features",
            "tags": null,
            "anonymous": 0,
            "reporter": "johannes"
        }
    ],
    "1317070": [
        {
            "ioc_value": "86.53.241.21:447",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-29 00:01:11",
            "last_seen_utc": "2026-08-11 02:46:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/86.53.241.21",
            "tags": "AS3257,C2,censys,GTT-BACKBONE,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1316522": [
        {
            "ioc_value": "107.22.165.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-27 04:00:34",
            "last_seen_utc": "2026-08-11 02:43:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/107.22.165.49",
            "tags": "AMAZON-AES,AS14618,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1314694": [
        {
            "ioc_value": "83.229.120.73:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2024-08-22 10:04:33",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/83.229.120.73",
            "tags": "AS139659,C2,censys,Mythic",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313657": [
        {
            "ioc_value": "193.19.242.55:1443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-19 19:55:59",
            "last_seen_utc": "2026-08-11 02:44:27",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/193.19.242.55",
            "tags": "AS35319,AS48964,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1313194": [
        {
            "ioc_value": "110.13.35.37:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-18 14:04:40",
            "last_seen_utc": "2026-08-11 02:43:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/110.13.35.37",
            "tags": "AS9318,C2,censys,RAT,SKB-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312402": [
        {
            "ioc_value": "20.188.119.195:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-17 14:04:20",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312338": [
        {
            "ioc_value": "210.249.114.154:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-17 02:04:24",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "AS2516,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1312117": [
        {
            "ioc_value": "20.188.119.195:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-08-16 14:02:33",
            "last_seen_utc": "2026-08-11 02:44:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.188.119.195",
            "tags": "AS8075,C2,censys,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1311619": [
        {
            "ioc_value": "23.24.178.35:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:43",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.35",
            "tags": "AS20214,C2,censys,COMCAST-20214,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1311614": [
        {
            "ioc_value": "120.25.239.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-08-15 22:40:39",
            "last_seen_utc": "2026-08-11 02:43:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/120.25.239.36",
            "tags": "ALIBABA-CN-NET,AS37963,C2,censys,RAT",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1310952": [
        {
            "ioc_value": "47.100.16.83:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-08-15 04:02:49",
            "last_seen_utc": "2026-08-11 02:47:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1309755": [
        {
            "ioc_value": "146.70.158.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-08-11 21:50:57",
            "last_seen_utc": "2026-08-11 02:43:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/146.70.158.198",
            "tags": "AS9009,C2,censys,M247",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1296480": [
        {
            "ioc_value": "43.138.0.179:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-07-09 19:05:36",
            "last_seen_utc": "2026-08-11 03:21:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1296006": [
        {
            "ioc_value": "213.149.181.121:469",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:58",
            "last_seen_utc": "2026-08-11 02:44:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/213.149.181.121",
            "tags": "CYTA-NETWORK Internet Services,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1296003": [
        {
            "ioc_value": "20.105.139.205:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-09 06:51:48",
            "last_seen_utc": "2026-08-11 02:44:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/20.105.139.205",
            "tags": "MICROSOFT-CORP-MSN-AS-BLOCK,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1295752": [
        {
            "ioc_value": "210.249.114.153:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-08 06:51:14",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1295405": [
        {
            "ioc_value": "23.24.178.33:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-07 03:48:38",
            "last_seen_utc": "2026-08-11 02:45:32",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/23.24.178.33",
            "tags": "COMCAST-7922,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1292877": [
        {
            "ioc_value": "210.249.114.154:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-03 06:52:14",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.154",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291417": [
        {
            "ioc_value": "198.244.197.118:9443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:40",
            "last_seen_utc": "2026-08-11 02:44:34",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/198.244.197.118",
            "tags": "NetSupportRAT,OVH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291414": [
        {
            "ioc_value": "206.210.123.104:8888",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:30",
            "last_seen_utc": "2026-08-11 02:44:43",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/206.210.123.104",
            "tags": "IASL,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291411": [
        {
            "ioc_value": "61.96.204.117:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:19",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/61.96.204.117",
            "tags": "DREAMX-AS DREAMLINE CO.,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291410": [
        {
            "ioc_value": "185.23.192.33:444",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:15",
            "last_seen_utc": "2026-08-11 02:44:19",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/185.23.192.33",
            "tags": "NetSupportRAT,WINET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291409": [
        {
            "ioc_value": "2.136.235.200:3085",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:05:10",
            "last_seen_utc": "2026-08-11 02:44:35",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/2.136.235.200",
            "tags": "NetSupportRAT,TELEFONICA_DE_ESPANA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291397": [
        {
            "ioc_value": "210.249.114.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.netsupportmanager_rat",
            "malware_alias": "NetSupport",
            "malware_printable": "NetSupportManager RAT",
            "first_seen_utc": "2024-07-01 10:04:31",
            "last_seen_utc": "2026-08-11 02:44:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/210.249.114.153",
            "tags": "KDDI KDDI CORPORATION,NetSupportRAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1291297": [
        {
            "ioc_value": "londopas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:04",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291296": [
        {
            "ioc_value": "berjimek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 21:00:03",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1291010": [
        {
            "ioc_value": "www.qianxinnbplus.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-30 10:13:19",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HKLNIL Landui Cloud ComputingHK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1289423": [
        {
            "ioc_value": "152.32.202.240:8443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-26 17:07:43",
            "last_seen_utc": "2026-08-11 02:47:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1287670": [
        {
            "ioc_value": "91.199.154.103:34211",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-06-22 06:45:48",
            "last_seen_utc": "2026-08-11 02:46:37",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/91.199.154.103",
            "tags": "Sliver",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1285430": [
        {
            "ioc_value": "ieee-ecce.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285431": [
        {
            "ioc_value": "kauzalvip.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285432": [
        {
            "ioc_value": "nakit-yok.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1285433": [
        {
            "ioc_value": "nathanhr.services",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-16 14:42:03",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1283657": [
        {
            "ioc_value": "support.whatsappsignup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-10 09:26:05",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,PEG TECH INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1278385": [
        {
            "ioc_value": "static.nvidiadrives.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 19:42:15",
            "last_seen_utc": "2026-08-11 03:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1278172": [
        {
            "ioc_value": "119.91.208.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-02 08:38:33",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277937": [
        {
            "ioc_value": "47.109.69.135:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-06-01 13:08:25",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1277588": [
        {
            "ioc_value": "101.43.32.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-31 12:57:33",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276810": [
        {
            "ioc_value": "asterchildrenshoes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:53:46",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BL Networks,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276802": [
        {
            "ioc_value": "124.223.41.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 12:52:55",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1276786": [
        {
            "ioc_value": "8.210.9.201:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-29 10:17:04",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,CobaltStrike,cs-watermark-0",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1275630": [
        {
            "ioc_value": "pt-security.ru",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-25 22:18:29",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MTW-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1274726": [
        {
            "ioc_value": "47.92.127.53:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-24 13:15:35",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273973": [
        {
            "ioc_value": "119.28.83.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-22 11:06:58",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273882": [
        {
            "ioc_value": "51.15.16.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "js.fakeupdates",
            "malware_alias": "FakeUpdate,GhoLoader,SocGholish",
            "malware_printable": "FAKEUPDATES",
            "first_seen_utc": "2024-05-21 18:51:48",
            "last_seen_utc": "2026-08-11 02:46:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/51.15.16.116",
            "tags": "Online SAS,SocGholish",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1273456": [
        {
            "ioc_value": "139.159.203.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-21 12:53:29",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1272788": [
        {
            "ioc_value": "123.58.198.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-19 07:56:13",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271699": [
        {
            "ioc_value": "vip8806.mom",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-16 07:53:43",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS LLC,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271605": [
        {
            "ioc_value": "blmdiscount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-08-11 03:21:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271606": [
        {
            "ioc_value": "91.238.181.235:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 22:13:26",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FBWNETWORKS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1271347": [
        {
            "ioc_value": "118.25.85.198:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-15 15:33:07",
            "last_seen_utc": "2026-08-11 03:21:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/118.25.85.198",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-305419896,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1270684": [
        {
            "ioc_value": "64.7.198.58:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-14 10:14:21",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BLNWX,CobaltStrike,cs-watermark-426352781",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269727": [
        {
            "ioc_value": "113.31.105.33:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:31",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "China Telecom (Group),CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269724": [
        {
            "ioc_value": "185.196.8.18:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:10",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269723": [
        {
            "ioc_value": "action-winds.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:09",
            "last_seen_utc": "2026-08-11 03:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1269721": [
        {
            "ioc_value": "microstar.cfd",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-11 22:47:08",
            "last_seen_utc": "2026-08-11 03:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Simple Carrier LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267565": [
        {
            "ioc_value": "113.31.106.106:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 10:14:57",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHINANET-SHANGHAI-MAN China Telecom Group,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1267486": [
        {
            "ioc_value": "111.230.12.238:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-07 07:48:08",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/111.230.12.238",
            "tags": "AS45090,c2,censys,CobaltStrike,cs-watermark-391144938,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1266959": [
        {
            "ioc_value": "134.122.130.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-05-06 12:49:25",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263972": [
        {
            "ioc_value": "134.122.130.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-29 12:51:26",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BGPNET Global ASN,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1263319": [
        {
            "ioc_value": "124.71.106.234:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-28 17:59:06",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262666": [
        {
            "ioc_value": "118.31.116.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-26 12:59:31",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1262568": [
        {
            "ioc_value": "8.134.11.7:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-25 22:12:56",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1261845": [
        {
            "ioc_value": "165.227.108.186:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-24 13:08:20",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-970865301,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260893": [
        {
            "ioc_value": "80.66.75.9:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:49",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GRIZ-INET-SERVICE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1260890": [
        {
            "ioc_value": "101.201.54.74:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-23 18:05:43",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1259796": [
        {
            "ioc_value": "62.204.41.11:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-21 15:09:17",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/62.204.41.11",
            "tags": "AS59425,c2,censys,CobaltStrike,cs-watermark-1580103824,HORIZONMSK-AS",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1258693": [
        {
            "ioc_value": "https://23.88.47.9/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-04-18 16:17:26",
            "last_seen_utc": "2026-08-11 03:29:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1255726": [
        {
            "ioc_value": "124.220.6.158:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:16",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1255727": [
        {
            "ioc_value": "124.220.6.158:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-11 10:15:15",
            "last_seen_utc": "2026-08-11 02:47:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&virtual_hosts=EXCLUDE&q=%28services.software.uniform_resource_identifier%3A+%60cpe%3A2.3%3Aa%3Afortra%3Acobalt_strike%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%3A%2A%60%29+and+autonomous_system.name%3D%60TENCENT-NET-AP+Shenzhen+Tencent+Computer+Systems+Company+Limited%60",
            "tags": "AS45090,c2,censys,CobaltStrike,TENCENT-NET-AP",
            "anonymous": 0,
            "reporter": "DonPasci"
        }
    ],
    "1252542": [
        {
            "ioc_value": "185.196.10.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-04-02 10:17:26",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,SIMPLECARRIER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1250157": [
        {
            "ioc_value": "soneypaly.club",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 14:42:02",
            "last_seen_utc": "2026-08-11 03:21:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1249815": [
        {
            "ioc_value": "47.105.69.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-27 07:57:29",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1248363": [
        {
            "ioc_value": "https://titnovacrion.top/live/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.unidentified_111",
            "malware_alias": "BLACKWIDOW,IceNova,Latrodectus,Lotus",
            "malware_printable": "Unidentified 111 (Latrodectus)",
            "first_seen_utc": "2024-03-22 19:47:18",
            "last_seen_utc": "2026-08-11 03:27:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "1245476": [
        {
            "ioc_value": "47.100.87.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-09 20:54:40",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244781": [
        {
            "ioc_value": "194.165.16.55:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 20:55:37",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1244726": [
        {
            "ioc_value": "googlesupportacc.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-03-06 10:12:56",
            "last_seen_utc": "2026-08-11 03:21:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASSEFLOW,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1241656": [
        {
            "ioc_value": "121.43.55.149:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-21 22:13:19",
            "last_seen_utc": "2026-08-11 03:21:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike,cs-watermark-391144938",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1237621": [
        {
            "ioc_value": "qw.regcssv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-07 10:12:21",
            "last_seen_utc": "2026-08-11 03:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,FLYSERVERS-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1236577": [
        {
            "ioc_value": "ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-03 19:38:15",
            "last_seen_utc": "2026-08-11 03:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.22.66.152+ec2-3-22-66-152.us-east-2.compute.amazonaws.com",
            "tags": "AMAZON-02,AS16509,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1236276": [
        {
            "ioc_value": "20.56.70.245:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-02-02 06:00:13",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1235332": [
        {
            "ioc_value": "www.louangelwolf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-30 06:20:34",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1551089073",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234854": [
        {
            "ioc_value": "kkudndkwatnfevcaqeefytqnh.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:18",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234859": [
        {
            "ioc_value": "whxzqkbbtzvdyxdeseoiyujzs.co",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234860": [
        {
            "ioc_value": "uohhunkmnfhbimtagizqgwpmv.to",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-28 06:22:17",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1234928": [
        {
            "ioc_value": "114.55.133.151:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:40",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/114.55.133.151",
            "tags": "AS37963,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234909": [
        {
            "ioc_value": "117.72.39.83:30005",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-27 14:31:20",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "AS141679,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1234304": [
        {
            "ioc_value": "38.147.189.199:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2024-01-24 18:49:24",
            "last_seen_utc": "2026-08-11 02:45:44",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/38.147.189.199",
            "tags": "Pupy RAT,XNNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1233919": [
        {
            "ioc_value": "www.idn15r69vh3fwhzclfoeuaoy.today",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-23 13:53:21",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.219.229.99+www.idn15r69vh3fwhzclfoeuaoy.today",
            "tags": "AS45102,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1231802": [
        {
            "ioc_value": "164-90-169-184.cprapid.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-18 13:44:13",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.169.184+164-90-169-184.cprapid.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1230963": [
        {
            "ioc_value": "https://65.21.187.53/",
            "ioc_type": "url",
            "threat_type": "botnet_cc",
            "malware": "win.vidar",
            "malware_alias": null,
            "malware_printable": "Vidar",
            "first_seen_utc": "2024-01-16 08:13:32",
            "last_seen_utc": "2026-08-11 03:10:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "Vidar",
            "anonymous": 0,
            "reporter": "crep1x"
        }
    ],
    "1230909": [
        {
            "ioc_value": "lz4.tiktok123.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-15 16:27:00",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230478": [
        {
            "ioc_value": "164.92.79.49:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-13 06:47:25",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.79.49",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1230429": [
        {
            "ioc_value": "site.dev.hutechweb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-12 18:36:24",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230076": [
        {
            "ioc_value": "ns1.fiducaire.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230077": [
        {
            "ioc_value": "ns1.asurances.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:21",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230078": [
        {
            "ioc_value": "sagsblog.telinduslab.lu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1263551644",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1230079": [
        {
            "ioc_value": "ns1.jocelynhealth.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-11 06:54:20",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1590258876",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229840": [
        {
            "ioc_value": "ns.emaratalyoum.me",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-10 10:50:13",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1727139162",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229817": [
        {
            "ioc_value": "161.35.239.147:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2024-01-10 06:48:20",
            "last_seen_utc": "2026-08-11 02:43:52",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/161.35.239.147",
            "tags": "DIGITALOCEAN-ASN,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229694": [
        {
            "ioc_value": "emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:19",
            "last_seen_utc": "2026-08-11 03:21:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229695": [
        {
            "ioc_value": "ns1.emailmigration.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 14:55:17",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "cobaltstrike,cs-watermark-1892870985",
            "anonymous": 0,
            "reporter": "myceliumbroker"
        }
    ],
    "1229661": [
        {
            "ioc_value": "111.92.243.236:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-09 08:45:29",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-666666666,HFTCL-AS-AP High Family Technology Co. Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1229599": [
        {
            "ioc_value": "82.65.19.134:4443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2024-01-09 05:30:32",
            "last_seen_utc": "2026-08-11 02:46:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.65.19.134",
            "tags": "C2,censys,PROXAD,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228458": [
        {
            "ioc_value": "139.9.62.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 21:31:13",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.9.62.19",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228181": [
        {
            "ioc_value": "101.133.225.51:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-05 14:48:41",
            "last_seen_utc": "2026-08-11 02:46:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.133.225.51",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1228033": [
        {
            "ioc_value": "143.110.151.209:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2024-01-05 06:45:36",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "DIGITALOCEAN-ASN,Sliver",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1227297": [
        {
            "ioc_value": "106.54.209.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2024-01-02 14:31:12",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/106.54.209.36",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1226488": [
        {
            "ioc_value": "astra4512.startdedicated.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-30 11:33:25",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,GD-EMEA-DC-SXB1",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1224105": [
        {
            "ioc_value": "cs.xcb.one",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-27 22:15:29",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1223678": [
        {
            "ioc_value": "8.140.203.92:7817",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-12-26 06:46:27",
            "last_seen_utc": "2026-08-11 02:46:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.140.203.92",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1221451": [
        {
            "ioc_value": "62.234.27.204:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-18 05:00:11",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1213636": [
        {
            "ioc_value": "MicrosoftSyst3m.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-16 22:12:14",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1213211": [
        {
            "ioc_value": "117.72.39.83:33333",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-15 18:59:31",
            "last_seen_utc": "2026-08-11 02:46:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.39.83",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1209246": [
        {
            "ioc_value": "unzip2.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-12-04 08:45:50",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1207072": [
        {
            "ioc_value": "60.205.115.92:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-28 13:32:35",
            "last_seen_utc": "2026-08-11 02:46:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/60.205.115.92",
            "tags": "C2,censys,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1206188": [
        {
            "ioc_value": "149.28.37.137:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-25 02:48:24",
            "last_seen_utc": "2026-08-10 09:05:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.37.137",
            "tags": "AS-CHOOPA,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1206189": [
        {
            "ioc_value": "149.28.37.137:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-25 02:48:24",
            "last_seen_utc": "2026-08-10 08:05:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/149.28.37.137",
            "tags": "AS-CHOOPA,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1205166": [
        {
            "ioc_value": "techsyscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205167": [
        {
            "ioc_value": "yify88.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:04",
            "last_seen_utc": "2026-08-11 03:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1205164": [
        {
            "ioc_value": "americcorp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-24 08:21:02",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1204685": [
        {
            "ioc_value": "tech-guard.vguard.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-22 20:04:09",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/44.204.120.159+tech-guard.vguard.tech",
            "tags": "AMAZON-AES,C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1202628": [
        {
            "ioc_value": "ns.manager.moonlighter.space",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-15 20:24:37",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1893164628,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1201144": [
        {
            "ioc_value": "101.34.222.38:60000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "apk.viper_rat",
            "malware_alias": null,
            "malware_printable": "Viper RAT",
            "first_seen_utc": "2023-11-09 17:50:07",
            "last_seen_utc": "2026-08-11 02:43:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/101.34.222.38",
            "tags": "C2,censys,RAT",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1200343": [
        {
            "ioc_value": "dev.theokanegroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-09 04:06:44",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/134.209.164.110+dev.theokanegroup.com",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199506": [
        {
            "ioc_value": "bwyb.love",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-06 18:07:30",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/47.242.158.114+bwyb.love",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1199160": [
        {
            "ioc_value": "www.sunwu.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-11-05 15:00:42",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/82.157.149.194+www.sunwu.world",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1192255": [
        {
            "ioc_value": "139.155.148.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-24 10:39:59",
            "last_seen_utc": "2026-08-11 03:21:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/139.155.148.131",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1191379": [
        {
            "ioc_value": "www.goocoinorg.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-20 21:57:56",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+www.goocoinorg.com&ref=threatfox",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1189545": [
        {
            "ioc_value": "airlinesapp.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-16 08:49:32",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,DigitalOcean LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1188605": [
        {
            "ioc_value": "lectricelfuel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-13 19:49:34",
            "last_seen_utc": "2026-08-11 03:21:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=INCLUDE&q=name%3A+lectricelfuel.com&ref=threatfox",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1187879": [
        {
            "ioc_value": "143.110.151.209:31337",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.sliver",
            "malware_alias": null,
            "malware_printable": "Sliver",
            "first_seen_utc": "2023-10-12 01:35:38",
            "last_seen_utc": "2026-08-11 02:43:33",
            "confidence_level": 90,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/143.110.151.209",
            "tags": "C2,censys,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1187462": [
        {
            "ioc_value": "117.72.8.192:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-10-11 12:59:56",
            "last_seen_utc": "2026-08-11 03:21:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/117.72.8.192",
            "tags": "C2,censys",
            "anonymous": 0,
            "reporter": "thehappydinoa"
        }
    ],
    "1180378": [
        {
            "ioc_value": "111.229.187.212:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-30 16:12:13",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 80,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "malpulse"
        }
    ],
    "1165497": [
        {
            "ioc_value": "igo0gle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-21 09:29:08",
            "last_seen_utc": "2026-08-11 03:21:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-ALVIVA,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1165172": [
        {
            "ioc_value": "8.217.217.243:8082",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-09-20 18:47:20",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.217.217.243",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155921": [
        {
            "ioc_value": "csxv.sec.cm",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-09 20:06:55",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHANGWAY-AS,CobaltStrike,cs-watermark-987654321",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1155319": [
        {
            "ioc_value": "43.136.38.59:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-09-05 21:52:59",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1152278": [
        {
            "ioc_value": "withoutedge.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:05",
            "last_seen_utc": "2026-08-11 03:21:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152277": [
        {
            "ioc_value": "thconnewfoot.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:04",
            "last_seen_utc": "2026-08-11 03:21:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152274": [
        {
            "ioc_value": "caixas.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-08-11 03:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152275": [
        {
            "ioc_value": "ddllsearch.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-08-11 03:21:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152276": [
        {
            "ioc_value": "gepcash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:03",
            "last_seen_utc": "2026-08-11 03:21:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152272": [
        {
            "ioc_value": "amazonclouds.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-08-11 03:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1152273": [
        {
            "ioc_value": "amur-city.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-26 18:42:02",
            "last_seen_utc": "2026-08-11 03:21:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1151932": [
        {
            "ioc_value": "77.74.208.123:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.havoc",
            "malware_alias": "Havokiz",
            "malware_printable": "Havoc",
            "first_seen_utc": "2023-08-25 06:48:54",
            "last_seen_utc": "2026-08-11 02:46:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/77.74.208.123",
            "tags": "BRETAGNETELECOM,Havoc",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1151693": [
        {
            "ioc_value": "43.153.222.28:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-23 11:56:21",
            "last_seen_utc": "2026-08-11 03:21:25",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149951": [
        {
            "ioc_value": "164.92.145.128:7810",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.brute_ratel_c4",
            "malware_alias": "BOLDBADGER,BruteRatel",
            "malware_printable": "Brute Ratel C4",
            "first_seen_utc": "2023-08-14 18:46:43",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.92.145.128",
            "tags": "Brute Ratel C4,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1149946": [
        {
            "ioc_value": "pctor.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:05",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149945": [
        {
            "ioc_value": "tehomics.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:04",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1149944": [
        {
            "ioc_value": "instant-healthonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-14 16:00:03",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1148731": [
        {
            "ioc_value": "stratpringl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-05 14:38:23",
            "last_seen_utc": "2026-08-11 03:21:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,PINDC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1148487": [
        {
            "ioc_value": "onlinetechdesk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-04 11:01:52",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146843": [
        {
            "ioc_value": "harmonyshoused.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:25:44",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146834": [
        {
            "ioc_value": "api.office-updates.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-03 10:24:41",
            "last_seen_utc": "2026-08-11 03:21:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-494165167,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1146619": [
        {
            "ioc_value": "mkbkygbgwcdc.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-08-02 10:24:58",
            "last_seen_utc": "2026-08-11 03:21:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-391144938,KAOPU-HK Kaopu Cloud HK Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1140114": [
        {
            "ioc_value": "tcessolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-25 10:17:22",
            "last_seen_utc": "2026-08-11 03:21:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS202973,CobaltStrike,cs-watermark-587247372",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1138196": [
        {
            "ioc_value": "rw1.sentrysource.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-15 12:48:31",
            "last_seen_utc": "2026-08-11 03:21:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-93937751,ROGERS-COMMUNICATIONS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1136628": [
        {
            "ioc_value": "198.13.42.85:53",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-07 19:56:07",
            "last_seen_utc": "2026-08-11 02:47:13",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,The Constant Company LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1136627": [
        {
            "ioc_value": "aaa.ad4min.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-07 19:56:05",
            "last_seen_utc": "2026-08-11 02:46:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-100000,The Constant Company LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1135804": [
        {
            "ioc_value": "pedagogists.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:02",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1135803": [
        {
            "ioc_value": "cdnsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-07-03 15:42:01",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1134787": [
        {
            "ioc_value": "1.15.248.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-28 22:51:22",
            "last_seen_utc": "2026-08-11 03:21:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-987654321,TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134128": [
        {
            "ioc_value": "check1.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:12:17",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1134127": [
        {
            "ioc_value": "check.judicical.ml",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-26 08:11:33",
            "last_seen_utc": "2026-08-11 02:46:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike,cs-watermark-100000000",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1133505": [
        {
            "ioc_value": "usadevgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-22 17:12:29",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,WAICORE-TRANSIT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1132563": [
        {
            "ioc_value": "103.27.186.185:9001",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-06-20 18:49:40",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.27.186.185",
            "tags": "Pupy RAT,SNL-HK Starry Network Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1128165": [
        {
            "ioc_value": "heastings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-11 22:26:06",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1127715": [
        {
            "ioc_value": "unitechdb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:05",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127713": [
        {
            "ioc_value": "cornptia.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127714": [
        {
            "ioc_value": "eyefinancemonitor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-09 20:00:04",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1127447": [
        {
            "ioc_value": "surplusofer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-08 16:27:41",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1126556": [
        {
            "ioc_value": "ns3.fuckworldxxx.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-05 09:01:38",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1126555": [
        {
            "ioc_value": "ns2.fuckworldxxx.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-05 09:01:11",
            "last_seen_utc": "2026-08-11 02:46:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1126554": [
        {
            "ioc_value": "ns1.fuckworldxxx.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-06-05 09:00:46",
            "last_seen_utc": "2026-08-11 02:46:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1234567890,Shenzhen Tencent Computer Systems Company Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122048": [
        {
            "ioc_value": "dianqi2.dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:42:02",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122047": [
        {
            "ioc_value": "dianqi1.dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:46",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122046": [
        {
            "ioc_value": "dianqi2.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:31",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1122045": [
        {
            "ioc_value": "dianqi1.jiayongdianqi.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-25 15:41:10",
            "last_seen_utc": "2026-08-11 02:46:47",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-492498911,XNNET LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1121460": [
        {
            "ioc_value": "update.microsoftapply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-24 19:35:48",
            "last_seen_utc": "2026-08-11 02:46:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-Not Found,DediPath",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1120772": [
        {
            "ioc_value": "australiansuper.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-23 12:37:36",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike,cs-watermark-348901740",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1116637": [
        {
            "ioc_value": "sheersdesigns.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:03",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1116636": [
        {
            "ioc_value": "artmicrodesign.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-16 10:00:02",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1114522": [
        {
            "ioc_value": "103.27.186.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-10 18:49:37",
            "last_seen_utc": "2026-08-11 02:43:07",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/103.27.186.185",
            "tags": "Pupy RAT,SNL-HK Starry Network Limited",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1112839": [
        {
            "ioc_value": "situotech.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-05-06 16:13:31",
            "last_seen_utc": "2026-08-11 03:21:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,HARMONYHOSTING-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1111492": [
        {
            "ioc_value": "157.245.155.179:9000",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.pupy",
            "malware_alias": "Patpoopy",
            "malware_printable": "pupy",
            "first_seen_utc": "2023-05-05 12:42:12",
            "last_seen_utc": "2026-08-11 02:43:48",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/157.245.155.179",
            "tags": "DIGITALOCEAN-ASN,Pupy RAT",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110863": [
        {
            "ioc_value": "39.106.36.96:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:43",
            "last_seen_utc": "2026-08-11 02:45:46",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/39.106.36.96",
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110862": [
        {
            "ioc_value": "36.95.131.171:9091",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:41",
            "last_seen_utc": "2026-08-11 02:45:41",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/36.95.131.171",
            "tags": "Deimos,TELKOMNET-AS-AP PT Telekomunikasi Indonesia",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110860": [
        {
            "ioc_value": "18.162.155.202:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:35",
            "last_seen_utc": "2026-08-11 02:44:11",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/18.162.155.202",
            "tags": "AMAZON-02,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110859": [
        {
            "ioc_value": "8.218.26.114:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:33",
            "last_seen_utc": "2026-08-11 02:46:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/8.218.26.114",
            "tags": "ALIBABA-CN-NET Alibaba US Technology Co. Ltd.,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1110858": [
        {
            "ioc_value": "3.209.12.178:3060",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.deimos",
            "malware_alias": null,
            "malware_printable": "Deimos",
            "first_seen_utc": "2023-05-04 06:46:30",
            "last_seen_utc": "2026-08-11 02:45:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/3.209.12.178",
            "tags": "AMAZON-AES,Deimos",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1106335": [
        {
            "ioc_value": "maboloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1106336": [
        {
            "ioc_value": "matong.buzz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-22 18:00:03",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1105988": [
        {
            "ioc_value": "qw.sveexec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-21 10:20:17",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1580103824,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1103771": [
        {
            "ioc_value": "77.242.250.36:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-15 12:28:52",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1416875320",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1102558": [
        {
            "ioc_value": "lls-rs.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-12 09:02:56",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-0,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1096685": [
        {
            "ioc_value": "iony.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096686": [
        {
            "ioc_value": "office36o.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:03",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096683": [
        {
            "ioc_value": "feyrijavac.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1096684": [
        {
            "ioc_value": "fidelyus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-04-03 07:21:02",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1095276": [
        {
            "ioc_value": "jacketsupport.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 22:27:30",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-587247372,GLOBALLAYER",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1095042": [
        {
            "ioc_value": "duckducklive.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-29 04:51:21",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.virustotal.com/gui/file/b5da1db6d69f2f872e603beb0f121c68f3320ed33a0c9835bfc1a931d177c947",
            "tags": "391144938,Beacon,Cobalt Strike,CobaltStrike",
            "anonymous": 0,
            "reporter": "AndreGironda"
        }
    ],
    "1094484": [
        {
            "ioc_value": "louvree.abudhabe.info",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-28 15:52:23",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1826426664,EMIRATES-INTERNET Emirates Internet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1092077": [
        {
            "ioc_value": "jquerymaingame.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092078": [
        {
            "ioc_value": "mail-my-account.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092079": [
        {
            "ioc_value": "my-accounts-gooogle.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092080": [
        {
            "ioc_value": "pegistrationads.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:02",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092075": [
        {
            "ioc_value": "eaglehardwares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092076": [
        {
            "ioc_value": "information.baby",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 17:21:01",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1092009": [
        {
            "ioc_value": "moviegallerys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-20 13:36:29",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-206546002,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091575": [
        {
            "ioc_value": "acroserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 22:40:17",
            "last_seen_utc": "2026-08-11 03:21:52",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091535": [
        {
            "ioc_value": "atechniques.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 19:45:49",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1091454": [
        {
            "ioc_value": "winsatoom.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-17 13:33:15",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-668694132",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1087542": [
        {
            "ioc_value": "devoinnanote.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-03-13 04:47:12",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-2130772225,SHARKTECH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082976": [
        {
            "ioc_value": "ponzinivek.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082977": [
        {
            "ioc_value": "ruplearben.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082978": [
        {
            "ioc_value": "talonbilling.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082979": [
        {
            "ioc_value": "gorillagaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082980": [
        {
            "ioc_value": "chanimoblie.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-26 09:03:09",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082871": [
        {
            "ioc_value": "kbnexc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:02",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082870": [
        {
            "ioc_value": "jquerysslx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 14:42:01",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1082838": [
        {
            "ioc_value": "e-servicesolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-25 13:15:07",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA GROUP Ltd,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082591": [
        {
            "ioc_value": "devsecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-24 02:30:56",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-674054486,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1082417": [
        {
            "ioc_value": "www.vmware.rest",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-23 13:06:07",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-CHOOPA,CobaltStrike,cs-watermark-1234567890",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1081018": [
        {
            "ioc_value": "galspost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-17 18:25:01",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,cs-watermark-1101991775,Microsoft Corporation",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1080735": [
        {
            "ioc_value": "imvcatool.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-16 14:54:22",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike,cs-watermark-674054486",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078198": [
        {
            "ioc_value": "aspnetcenter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 19:39:46",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Web Gostaran Bandar Company PJS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1078172": [
        {
            "ioc_value": "audelr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078173": [
        {
            "ioc_value": "csou.link",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078174": [
        {
            "ioc_value": "integrated-security.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078175": [
        {
            "ioc_value": "uranustechsolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-04 18:42:02",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1078062": [
        {
            "ioc_value": "getsafeblog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 17:24:39",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1077913": [
        {
            "ioc_value": "39.107.242.125:80",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-03 00:16:03",
            "last_seen_utc": "2026-08-11 02:47:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://www.redpacketsecurity.com/cobalt-stike-beacon-detected-39-107-242-125-port-80/",
            "tags": "CobaltStrike,RedPacketSecurity",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1076907": [
        {
            "ioc_value": "qw.svcshosvt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:40:26",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1076896": [
        {
            "ioc_value": "nxsimdevelop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-02 19:39:18",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075651": [
        {
            "ioc_value": "appdevtechnology.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-02-01 02:21:19",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075540": [
        {
            "ioc_value": "dbx.formsift.io",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-31 15:09:13",
            "last_seen_utc": "2026-08-11 03:21:53",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1075020": [
        {
            "ioc_value": "devcloudpro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-29 11:29:55",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074894": [
        {
            "ioc_value": "164.90.158.199:7443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "unknown",
            "malware_alias": null,
            "malware_printable": "Unknown malware",
            "first_seen_utc": "2023-01-28 09:40:24",
            "last_seen_utc": "2026-08-11 02:43:55",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "https://search.censys.io/hosts/164.90.158.199",
            "tags": "DIGITALOCEAN-ASN,Mythic",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1074144": [
        {
            "ioc_value": "support-wellsfargovis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:03",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074141": [
        {
            "ioc_value": "recoverporta1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074142": [
        {
            "ioc_value": "recoverportal2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1074143": [
        {
            "ioc_value": "recoveryweb2.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-25 19:42:02",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1073670": [
        {
            "ioc_value": "vd-ntds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-23 20:33:42",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PROSPERO-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1070164": [
        {
            "ioc_value": "hnsxpharm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070165": [
        {
            "ioc_value": "myjqueryss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070167": [
        {
            "ioc_value": "telusmobility-billed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070168": [
        {
            "ioc_value": "thenbkgroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 14:21:02",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1070137": [
        {
            "ioc_value": "avdev.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-20 11:23:14",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Flyservers S.A.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069980": [
        {
            "ioc_value": "qw.execsvct.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 19:53:20",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069895": [
        {
            "ioc_value": "azurecloudfire.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 14:15:53",
            "last_seen_utc": "2026-08-11 03:21:56",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ITRESHENIYA-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069868": [
        {
            "ioc_value": "goupdatemic.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-19 11:23:42",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GOOGLE",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1069579": [
        {
            "ioc_value": "mwg-update.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-18 02:29:29",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068206": [
        {
            "ioc_value": "goodsport2023.win",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-13 17:37:32",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,VOM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068079": [
        {
            "ioc_value": "blackandwhiteshoose.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 21:56:23",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1068045": [
        {
            "ioc_value": "qw.svcrencst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 20:55:06",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067954": [
        {
            "ioc_value": "realsecuritystore.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 14:45:18",
            "last_seen_utc": "2026-08-11 03:21:57",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067924": [
        {
            "ioc_value": "fixx.sbs",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-12 13:04:56",
            "last_seen_utc": "2026-08-11 03:21:54",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SNEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1067646": [
        {
            "ioc_value": "allowedcloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2023-01-11 10:59:45",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HIVELOCITY Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064196": [
        {
            "ioc_value": "freegaysnews.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 19:48:39",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS2-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064176": [
        {
            "ioc_value": "topgamenetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 18:58:09",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1064173": [
        {
            "ioc_value": "zfuxwvouqvnttpsrxe.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-31 16:21:02",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064075": [
        {
            "ioc_value": "cloudyspaces.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-08-11 03:22:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064076": [
        {
            "ioc_value": "666621.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:52",
            "last_seen_utc": "2026-08-11 03:22:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064069": [
        {
            "ioc_value": "144.217.207.19:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064070": [
        {
            "ioc_value": "allsdone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064071": [
        {
            "ioc_value": "ipsandwich.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064072": [
        {
            "ioc_value": "cookieholder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064073": [
        {
            "ioc_value": "pingcheker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-11 03:22:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064074": [
        {
            "ioc_value": "wagonovk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:51",
            "last_seen_utc": "2026-08-11 03:22:51",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064062": [
        {
            "ioc_value": "microsoftupdateassist.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064063": [
        {
            "ioc_value": "qvibova.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064064": [
        {
            "ioc_value": "cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064065": [
        {
            "ioc_value": "metalkost.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064066": [
        {
            "ioc_value": "m7r4r2i2.stackpathcdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064067": [
        {
            "ioc_value": "online.cloudwebpictures.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:50",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064057": [
        {
            "ioc_value": "bartiba.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064058": [
        {
            "ioc_value": "varnart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064059": [
        {
            "ioc_value": "nsfdfdfdf.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064060": [
        {
            "ioc_value": "micorsoft.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064061": [
        {
            "ioc_value": "aigouing.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:49",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064046": [
        {
            "ioc_value": "ksplsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064047": [
        {
            "ioc_value": "lastinsuranceteam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064048": [
        {
            "ioc_value": "msdnsservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064049": [
        {
            "ioc_value": "securequoteme.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064050": [
        {
            "ioc_value": "techdevcorp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064051": [
        {
            "ioc_value": "syncorporation.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064052": [
        {
            "ioc_value": "visualstudioapp.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064053": [
        {
            "ioc_value": "altreeservicellc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064054": [
        {
            "ioc_value": "discountshadesdirect.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064055": [
        {
            "ioc_value": "setechnowork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064056": [
        {
            "ioc_value": "technicollit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:48",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064038": [
        {
            "ioc_value": "shiyicaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064039": [
        {
            "ioc_value": "cdn-top.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064040": [
        {
            "ioc_value": "onesecondservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064041": [
        {
            "ioc_value": "vpnupdaters.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064042": [
        {
            "ioc_value": "rodinscoldly.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064043": [
        {
            "ioc_value": "antariscapital.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064044": [
        {
            "ioc_value": "ftwealthmgt.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064045": [
        {
            "ioc_value": "iconiq-capitel.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:47",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064031": [
        {
            "ioc_value": "asset-trades.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064032": [
        {
            "ioc_value": "telemetrin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064033": [
        {
            "ioc_value": "secupdate4win.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064034": [
        {
            "ioc_value": "cdn-start.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064035": [
        {
            "ioc_value": "capitalmanagementdata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064036": [
        {
            "ioc_value": "lawsolutions.cloud",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:46",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064024": [
        {
            "ioc_value": "diegomaster.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064025": [
        {
            "ioc_value": "dp-test1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064026": [
        {
            "ioc_value": "cloudkey.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064027": [
        {
            "ioc_value": "updatevpncitrix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064028": [
        {
            "ioc_value": "classgum.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064029": [
        {
            "ioc_value": "edgeupdater.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064030": [
        {
            "ioc_value": "gfcbm.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:45",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064016": [
        {
            "ioc_value": "barmnava.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064017": [
        {
            "ioc_value": "firewallwithadvancedserurity.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064018": [
        {
            "ioc_value": "lgbtqplusfriendlydomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064019": [
        {
            "ioc_value": "market-stats.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064020": [
        {
            "ioc_value": "apabfs.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064021": [
        {
            "ioc_value": "fziomerof.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064022": [
        {
            "ioc_value": "fserd.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064023": [
        {
            "ioc_value": "verofes.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:44",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064015": [
        {
            "ioc_value": "postofficeltdc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:43",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064006": [
        {
            "ioc_value": "jarvcza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064007": [
        {
            "ioc_value": "teystyjeem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064008": [
        {
            "ioc_value": "faceupfinder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064009": [
        {
            "ioc_value": "costacancordia.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064010": [
        {
            "ioc_value": "lapsusareskids.world",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064011": [
        {
            "ioc_value": "msupdater.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064012": [
        {
            "ioc_value": "dwordname.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064013": [
        {
            "ioc_value": "trademot.finance",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064014": [
        {
            "ioc_value": "agreminj.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:42",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063998": [
        {
            "ioc_value": "exchangeallltd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063999": [
        {
            "ioc_value": "guggenheimpartners-survey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064000": [
        {
            "ioc_value": "caresalonservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064001": [
        {
            "ioc_value": "just-findncall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064002": [
        {
            "ioc_value": "fluoxi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064003": [
        {
            "ioc_value": "buynet.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064004": [
        {
            "ioc_value": "everythingchecker.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1064005": [
        {
            "ioc_value": "dezword.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:41",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063995": [
        {
            "ioc_value": "goksearch.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063996": [
        {
            "ioc_value": "polyhaz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063997": [
        {
            "ioc_value": "data-protection-test.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:40",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063992": [
        {
            "ioc_value": "update04.microsoft-essentials.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:39",
            "last_seen_utc": "2026-08-11 03:22:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063991": [
        {
            "ioc_value": "akaluij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:38",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063989": [
        {
            "ioc_value": "43.129.7.189:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-08-11 03:22:33",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063990": [
        {
            "ioc_value": "82.156.241.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:36",
            "last_seen_utc": "2026-08-11 03:22:37",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063985": [
        {
            "ioc_value": "donormix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063986": [
        {
            "ioc_value": "hardicki.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063987": [
        {
            "ioc_value": "stfconnect.onthewifi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063988": [
        {
            "ioc_value": "agsdef.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:33",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063978": [
        {
            "ioc_value": "observerinfo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063979": [
        {
            "ioc_value": "dehikz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063980": [
        {
            "ioc_value": "cocanewline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063981": [
        {
            "ioc_value": "rainqor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063982": [
        {
            "ioc_value": "axelkim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063983": [
        {
            "ioc_value": "azimurs.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063984": [
        {
            "ioc_value": "innovativesitecreations.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:32",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063972": [
        {
            "ioc_value": "creditscore.usbankcreditcards.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063975": [
        {
            "ioc_value": "megumin.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063976": [
        {
            "ioc_value": "loanhelp.support",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063977": [
        {
            "ioc_value": "volsecure.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:31",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063966": [
        {
            "ioc_value": "domtern.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063968": [
        {
            "ioc_value": "drakr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063969": [
        {
            "ioc_value": "devcisco.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063971": [
        {
            "ioc_value": "web-news-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:30",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063963": [
        {
            "ioc_value": "bankafrika.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063964": [
        {
            "ioc_value": "mssfr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063965": [
        {
            "ioc_value": "edgekey.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:29",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063955": [
        {
            "ioc_value": "webyoutubeshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063956": [
        {
            "ioc_value": "extic.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063957": [
        {
            "ioc_value": "reykh.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063959": [
        {
            "ioc_value": "propertynewsclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063960": [
        {
            "ioc_value": "afindisc.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063961": [
        {
            "ioc_value": "propertyinfogroup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063962": [
        {
            "ioc_value": "topnewscompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:28",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063950": [
        {
            "ioc_value": "baidenfree.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063951": [
        {
            "ioc_value": "directoryupdate.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063952": [
        {
            "ioc_value": "azmnetwork.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063953": [
        {
            "ioc_value": "onevisioncommunications.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063954": [
        {
            "ioc_value": "campioni-imam.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:27",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063943": [
        {
            "ioc_value": "serviceapp1.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063944": [
        {
            "ioc_value": "softcloud.digital",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063945": [
        {
            "ioc_value": "appmind.center",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063946": [
        {
            "ioc_value": "ms-data.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063947": [
        {
            "ioc_value": "oracleup.cc",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063948": [
        {
            "ioc_value": "topinfocompany.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063949": [
        {
            "ioc_value": "blockchainstartups-crypto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:26",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063934": [
        {
            "ioc_value": "expresssmash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063935": [
        {
            "ioc_value": "vgroz.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063936": [
        {
            "ioc_value": "baidengop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063937": [
        {
            "ioc_value": "ofilopex.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063938": [
        {
            "ioc_value": "aabancaa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063939": [
        {
            "ioc_value": "shermango.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063940": [
        {
            "ioc_value": "nongxinyin.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063941": [
        {
            "ioc_value": "a6m1n.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063942": [
        {
            "ioc_value": "emailbox.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:25",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063926": [
        {
            "ioc_value": "wxtencent.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063927": [
        {
            "ioc_value": "emergeno.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063928": [
        {
            "ioc_value": "browngreeer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063929": [
        {
            "ioc_value": "processdec.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063931": [
        {
            "ioc_value": "sndm-sndm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063932": [
        {
            "ioc_value": "sinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063933": [
        {
            "ioc_value": "vinergil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:24",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063918": [
        {
            "ioc_value": "westtherr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063919": [
        {
            "ioc_value": "quickaccestwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063920": [
        {
            "ioc_value": "usgrim.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063921": [
        {
            "ioc_value": "onelivemusicshop.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063922": [
        {
            "ioc_value": "zomerax.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063923": [
        {
            "ioc_value": "fsamon.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063924": [
        {
            "ioc_value": "sscimails.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063925": [
        {
            "ioc_value": "agentrecovery.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:23",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063909": [
        {
            "ioc_value": "entertainok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063910": [
        {
            "ioc_value": "jatafatuna.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063911": [
        {
            "ioc_value": "pluyk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063912": [
        {
            "ioc_value": "affinm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063913": [
        {
            "ioc_value": "gijoxupe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063914": [
        {
            "ioc_value": "vangshares.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063915": [
        {
            "ioc_value": "fudupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063917": [
        {
            "ioc_value": "contemporaryto.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:22",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063902": [
        {
            "ioc_value": "ziono.xyz",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063903": [
        {
            "ioc_value": "lolutow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063904": [
        {
            "ioc_value": "niht12.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063905": [
        {
            "ioc_value": "slfcorporate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063906": [
        {
            "ioc_value": "baidu-cdn-10.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063907": [
        {
            "ioc_value": "jandoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063908": [
        {
            "ioc_value": "casevor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:21",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063897": [
        {
            "ioc_value": "gotroops.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063898": [
        {
            "ioc_value": "wtxservice.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063899": [
        {
            "ioc_value": "xevayuhace.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063900": [
        {
            "ioc_value": "suppcat.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063901": [
        {
            "ioc_value": "softloadup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:20",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063889": [
        {
            "ioc_value": "asbetysh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063890": [
        {
            "ioc_value": "ascagliarinish.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063891": [
        {
            "ioc_value": "ascasdsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063892": [
        {
            "ioc_value": "aschamp79sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063893": [
        {
            "ioc_value": "aschnurmansh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063894": [
        {
            "ioc_value": "aseleeeksh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063895": [
        {
            "ioc_value": "asensvsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:19",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063880": [
        {
            "ioc_value": "artist2actresssh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063881": [
        {
            "ioc_value": "arturprikhodkosh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063882": [
        {
            "ioc_value": "arvin78sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063883": [
        {
            "ioc_value": "arvind567shahsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063884": [
        {
            "ioc_value": "arvindkkumsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063885": [
        {
            "ioc_value": "arvosash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063886": [
        {
            "ioc_value": "arwalsersh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063887": [
        {
            "ioc_value": "aryaarieash.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063888": [
        {
            "ioc_value": "aryalalexsh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:18",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063870": [
        {
            "ioc_value": "dovaxanil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063871": [
        {
            "ioc_value": "hehegahu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063872": [
        {
            "ioc_value": "agriculturemachineries.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063873": [
        {
            "ioc_value": "arhipenkolenagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063874": [
        {
            "ioc_value": "aritmiagenesh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063875": [
        {
            "ioc_value": "artes911sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063876": [
        {
            "ioc_value": "arthas89sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063877": [
        {
            "ioc_value": "arthurstevens62sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063878": [
        {
            "ioc_value": "arthurtaylor13sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063879": [
        {
            "ioc_value": "artis214sh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:17",
            "last_seen_utc": "2026-08-11 03:22:13",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063864": [
        {
            "ioc_value": "zipo-cons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063865": [
        {
            "ioc_value": "fazehotafa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063866": [
        {
            "ioc_value": "zendriol.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063867": [
        {
            "ioc_value": "sezezapa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063868": [
        {
            "ioc_value": "sorekipe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063869": [
        {
            "ioc_value": "zezinuwe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:16",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063858": [
        {
            "ioc_value": "shrekf.art",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063859": [
        {
            "ioc_value": "amaniza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063860": [
        {
            "ioc_value": "microcloud.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063861": [
        {
            "ioc_value": "anexuss.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063862": [
        {
            "ioc_value": "edictsoft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063863": [
        {
            "ioc_value": "out1etshops.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:15",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063851": [
        {
            "ioc_value": "stepnbayac.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063852": [
        {
            "ioc_value": "chickenpoken.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063853": [
        {
            "ioc_value": "hockeysmall.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063854": [
        {
            "ioc_value": "orthodoxok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063855": [
        {
            "ioc_value": "cocesovo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063856": [
        {
            "ioc_value": "familyinsurancepartner.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063857": [
        {
            "ioc_value": "senebuvuyi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:14",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063848": [
        {
            "ioc_value": "fincheck.site",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063849": [
        {
            "ioc_value": "svchosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063850": [
        {
            "ioc_value": "conhosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:13",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063843": [
        {
            "ioc_value": "maximumservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063844": [
        {
            "ioc_value": "conferencedesk.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063845": [
        {
            "ioc_value": "bluetechsupply.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063846": [
        {
            "ioc_value": "allgroupservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063847": [
        {
            "ioc_value": "acitopram.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:12",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063838": [
        {
            "ioc_value": "businessservicesolution.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063839": [
        {
            "ioc_value": "gravyblicus.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063840": [
        {
            "ioc_value": "firmwarekey.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063841": [
        {
            "ioc_value": "updateraccount.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-11 03:22:48",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063842": [
        {
            "ioc_value": "mvnetworking.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:11",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063832": [
        {
            "ioc_value": "avasecurityservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063833": [
        {
            "ioc_value": "extranetserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063834": [
        {
            "ioc_value": "clacem.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063835": [
        {
            "ioc_value": "eonline-cdn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063836": [
        {
            "ioc_value": "cagohufe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063837": [
        {
            "ioc_value": "vezawahoy.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:10",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063826": [
        {
            "ioc_value": "tetafup.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063827": [
        {
            "ioc_value": "api-trend-micro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063828": [
        {
            "ioc_value": "digital-hardware.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063829": [
        {
            "ioc_value": "aboutdatabasesoftware.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063830": [
        {
            "ioc_value": "high-control.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063831": [
        {
            "ioc_value": "soft-base.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:09",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063821": [
        {
            "ioc_value": "iptvr.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063823": [
        {
            "ioc_value": "mingw.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063824": [
        {
            "ioc_value": "transfercloud.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063825": [
        {
            "ioc_value": "flashcom.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:08",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063818": [
        {
            "ioc_value": "sciencelifedata.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063819": [
        {
            "ioc_value": "bookingsupport.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063820": [
        {
            "ioc_value": "ateyakima.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:07",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063813": [
        {
            "ioc_value": "buy1walmart.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063816": [
        {
            "ioc_value": "drbeat.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063817": [
        {
            "ioc_value": "aialadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:06",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063810": [
        {
            "ioc_value": "hhkj222.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063811": [
        {
            "ioc_value": "yw2204.shop",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063812": [
        {
            "ioc_value": "nordicqlobal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:05",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063806": [
        {
            "ioc_value": "favls.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063807": [
        {
            "ioc_value": "linkkedin.life",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063808": [
        {
            "ioc_value": "magellanfit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:04",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063805": [
        {
            "ioc_value": "afspd.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:48:03",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063804": [
        {
            "ioc_value": "164.92.70.225:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:46:51",
            "last_seen_utc": "2026-08-11 03:22:30",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063802": [
        {
            "ioc_value": "abritrum-bridges.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-30 19:44:07",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://threatview.io/Downloads/High-Confidence-CobaltstrikeC2_platforms.txt",
            "tags": "CobaltStrike,threatview-io",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1063208": [
        {
            "ioc_value": "a.wv2022.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 19:56:09",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1063123": [
        {
            "ioc_value": "apacheorg.wiki",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-28 02:22:09",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDIE-AS-AP Cloudie Limited,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1062406": [
        {
            "ioc_value": "updatemicrotok.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-24 19:00:50",
            "last_seen_utc": "2026-08-11 03:21:58",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-SERVERION,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1053949": [
        {
            "ioc_value": "eserverx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 21:43:42",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AEZA-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050306": [
        {
            "ioc_value": "cmdatabase.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-19 11:41:44",
            "last_seen_utc": "2026-08-11 03:21:55",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ADM Service Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1050198": [
        {
            "ioc_value": "cloudmane.online",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-17 12:12:59",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036758": [
        {
            "ioc_value": "8.212.49.116:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-13 11:43:38",
            "last_seen_utc": "2026-08-11 03:21:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Alibaba (US) Technology Co. Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1036111": [
        {
            "ioc_value": "qw.conhoosst.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-12 01:38:31",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035723": [
        {
            "ioc_value": "expoglobalservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-08 20:45:56",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TIER-NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1035558": [
        {
            "ioc_value": "www.microsofer.top",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-07 20:05:59",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1031731": [
        {
            "ioc_value": "googlecontentuser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 20:03:53",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/TheDFIRReport/status/1599780643222654976",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1031726": [
        {
            "ioc_value": "test.227api.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 19:27:32",
            "last_seen_utc": "2026-08-11 03:21:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YISUCLOUDLTD-HK YISU CLOUD LTD",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1029025": [
        {
            "ioc_value": "palalto.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-05 11:42:38",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Private Layer INC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028963": [
        {
            "ioc_value": "esoftwareupdates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-04 20:18:27",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASGHOSTNET,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028767": [
        {
            "ioc_value": "globalplayservices.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 21:28:11",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028737": [
        {
            "ioc_value": "rapidfinact.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:50:52",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028720": [
        {
            "ioc_value": "globalsteamclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-02 20:38:18",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1028501": [
        {
            "ioc_value": "get-music-online.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-12-01 20:32:20",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1024554": [
        {
            "ioc_value": "msndla.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-27 16:10:54",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023854": [
        {
            "ioc_value": "childhealthresources.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:54:46",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1023821": [
        {
            "ioc_value": "360safeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-24 11:50:52",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1021044": [
        {
            "ioc_value": "aksaholdings.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-20 10:32:06",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1012628": [
        {
            "ioc_value": "msisfx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-15 06:56:25",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/malware_traffic/status/1592262598195646464",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "1009773": [
        {
            "ioc_value": "get-smartbuyer.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-12 17:46:46",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "1000509": [
        {
            "ioc_value": "qw.stakcl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-10 11:51:33",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "991420": [
        {
            "ioc_value": "sogouupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-08 20:20:30",
            "last_seen_utc": "2026-08-11 03:21:59",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "985010": [
        {
            "ioc_value": "dnsupdatecheck.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-07 20:10:29",
            "last_seen_utc": "2026-08-11 03:22:00",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "973832": [
        {
            "ioc_value": "ipulsecloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-04 11:23:08",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,FLYSERVERS-ENDCLIENTS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "964538": [
        {
            "ioc_value": "zadiguser.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964540": [
        {
            "ioc_value": "wasazokiwo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964541": [
        {
            "ioc_value": "yuwajeni.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964542": [
        {
            "ioc_value": "yavahiyil.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964543": [
        {
            "ioc_value": "rabihino.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964545": [
        {
            "ioc_value": "nokevohoh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964546": [
        {
            "ioc_value": "rawocav.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "964548": [
        {
            "ioc_value": "deyikurihe.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-11-03 12:12:17",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 1,
            "reporter": "anonymous"
        }
    ],
    "952862": [
        {
            "ioc_value": "freshuper.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-30 19:51:44",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,tzulo inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952596": [
        {
            "ioc_value": "reebons.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:32:13",
            "last_seen_utc": "2026-08-11 03:22:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952587": [
        {
            "ioc_value": "gaswert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 12:23:49",
            "last_seen_utc": "2026-08-11 03:22:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952582": [
        {
            "ioc_value": "sajij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 11:54:42",
            "last_seen_utc": "2026-08-11 03:22:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952555": [
        {
            "ioc_value": "asasyz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:14:36",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952552": [
        {
            "ioc_value": "agazud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 10:12:26",
            "last_seen_utc": "2026-08-11 03:22:02",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LLC Baxet",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952534": [
        {
            "ioc_value": "tuuik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:57:36",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,GLOBAL INTERNET SOLUTIONS LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "952528": [
        {
            "ioc_value": "alfuhin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-29 09:56:46",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "950974": [
        {
            "ioc_value": "amaladin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-27 23:43:27",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "949937": [
        {
            "ioc_value": "aualadin.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-26 10:09:11",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916136": [
        {
            "ioc_value": "bthserv.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:42:10",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Internet Solutions & Innovations LTD.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916115": [
        {
            "ioc_value": "nuesro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:37:35",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Partner LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "916100": [
        {
            "ioc_value": "pasadonline.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-23 13:36:50",
            "last_seen_utc": "2026-08-11 03:22:01",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915911": [
        {
            "ioc_value": "worldsgates.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:40:40",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LUCIDACLOUD LIMITED",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915908": [
        {
            "ioc_value": "protramal.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 19:39:30",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Perviy TSOD LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "915846": [
        {
            "ioc_value": "spltst.icu",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-22 01:11:02",
            "last_seen_utc": "2026-08-11 03:22:03",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,combahton GmbH",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891477": [
        {
            "ioc_value": "cehocihit.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 13:10:54",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "891461": [
        {
            "ioc_value": "cloudmicro.pro",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-16 12:38:04",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PLI-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "887212": [
        {
            "ioc_value": "keycloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:41:28",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PARTNER-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886703": [
        {
            "ioc_value": "activeservers.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:13:41",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amati Foundation,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886693": [
        {
            "ioc_value": "newyearbalance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:12:51",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CHERRYSERVERS3-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886516": [
        {
            "ioc_value": "xamayojir.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 21:02:36",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "886499": [
        {
            "ioc_value": "xicefoga.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 20:58:25",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-WDC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "884091": [
        {
            "ioc_value": "ams-prd-cob.nl",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:51:56",
            "last_seen_utc": "2026-08-11 03:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883488": [
        {
            "ioc_value": "tagujog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:35:22",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-PHX",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883412": [
        {
            "ioc_value": "mysqlserver.org",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:32:23",
            "last_seen_utc": "2026-08-11 03:22:15",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ICME",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "883142": [
        {
            "ioc_value": "xuluxetas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-13 19:23:44",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,LEASEWEB-USA-NYC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "880419": [
        {
            "ioc_value": "hadujaza.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-12 17:16:11",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871733": [
        {
            "ioc_value": "softsupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-08-11 03:22:04",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "871734": [
        {
            "ioc_value": "anushl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-10-05 18:54:33",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1577718910652129280",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858399": [
        {
            "ioc_value": "anbush.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-11 03:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858402": [
        {
            "ioc_value": "get-topservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858403": [
        {
            "ioc_value": "msoftupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "858404": [
        {
            "ioc_value": "pregabas.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-29 08:45:45",
            "last_seen_utc": "2026-08-11 03:22:05",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1575364140285267970",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "851096": [
        {
            "ioc_value": "34.92.131.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-22 11:26:18",
            "last_seen_utc": "2026-08-11 03:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Google LLC",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "850706": [
        {
            "ioc_value": "87.246.7.38:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:58:14",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850701": [
        {
            "ioc_value": "cloudmicro.tech",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-08-11 03:22:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850702": [
        {
            "ioc_value": "fregiyu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-08-11 03:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850704": [
        {
            "ioc_value": "microcloud.live",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-20 16:57:02",
            "last_seen_utc": "2026-08-11 03:22:06",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1572261285139714051",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "850260": [
        {
            "ioc_value": "154.22.117.31:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-17 21:24:41",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Cogent Communications",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "849761": [
        {
            "ioc_value": "198.98.53.34:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-14 22:07:14",
            "last_seen_utc": "2026-08-11 03:22:08",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,PONYNET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "847988": [
        {
            "ioc_value": "globallookclub.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:52",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847986": [
        {
            "ioc_value": "realfunsolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:50",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847972": [
        {
            "ioc_value": "www.service1app.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847975": [
        {
            "ioc_value": "youronlinesports.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847976": [
        {
            "ioc_value": "yourinfosolutions.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847978": [
        {
            "ioc_value": "login.onemusic24.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847981": [
        {
            "ioc_value": "zx.jacollans.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:48",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847942": [
        {
            "ioc_value": "satorkar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847943": [
        {
            "ioc_value": "er.theinfoinc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847957": [
        {
            "ioc_value": "realmacnow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847958": [
        {
            "ioc_value": "onemusicllc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847959": [
        {
            "ioc_value": "ateliernow.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847960": [
        {
            "ioc_value": "er.dropklant.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:47",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847929": [
        {
            "ioc_value": "sprinthunter.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847930": [
        {
            "ioc_value": "newstamagavk.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847934": [
        {
            "ioc_value": "www.onestepstar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-09-05 19:10:46",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847124": [
        {
            "ioc_value": "115.75.66.68:7707",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:17",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847123": [
        {
            "ioc_value": "115.75.66.68:6821",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:16",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847122": [
        {
            "ioc_value": "115.75.66.68:6606",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:45:14",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/8f7649bc068b21404fe08229026859aaa468634963eca11cc64b661fa64a6880/",
            "tags": "asyncrat",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847121": [
        {
            "ioc_value": "115.75.66.68:8808",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.asyncrat",
            "malware_alias": null,
            "malware_printable": "AsyncRAT",
            "first_seen_utc": "2022-09-01 06:40:24",
            "last_seen_utc": "2026-08-11 02:43:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AsyncRAT,RAT",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847028": [
        {
            "ioc_value": "barabezo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 18:29:19",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://bazaar.abuse.ch/sample/08ec3f13e8637a08dd763af6ccb46ff8516bc46efaacb1e5f052ada634a90c0e/",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "847018": [
        {
            "ioc_value": "alojun.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847019": [
        {
            "ioc_value": "asdder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-08-11 03:22:10",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "847020": [
        {
            "ioc_value": "www.zominoz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-31 16:32:01",
            "last_seen_utc": "2026-08-11 03:22:11",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "_ik_"
        }
    ],
    "846258": [
        {
            "ioc_value": "jevomukif.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-30 06:22:11",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-29-IOCs-for-Monster-Libra-TA551-IcedID-with-Cobalt-Stike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844214": [
        {
            "ioc_value": "msdnupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-08-11 03:22:16",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "844215": [
        {
            "ioc_value": "msdupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-20 06:53:07",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843958": [
        {
            "ioc_value": "caxoxc.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-18 12:15:06",
            "last_seen_utc": "2026-08-11 03:22:17",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "843546": [
        {
            "ioc_value": "47.108.180.121:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-16 11:38:21",
            "last_seen_utc": "2026-08-11 03:21:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,Hangzhou Alibaba Advertising Co.Ltd.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "842464": [
        {
            "ioc_value": "jahojahi.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-11 06:03:19",
            "last_seen_utc": "2026-08-11 03:22:12",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://raw.githubusercontent.com/pan-unit42/tweets/master/2022-08-10-IOCs-for-IcedID-and-Cobalt-Strike.txt",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "841613": [
        {
            "ioc_value": "zambeziz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-08-06 07:00:06",
            "last_seen_utc": "2026-08-11 03:22:18",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": "CobaltSrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "839793": [
        {
            "ioc_value": "zuyonijobo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-27 08:49:04",
            "last_seen_utc": "2026-08-11 03:22:19",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://isc.sans.edu/diary/28884",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "802793": [
        {
            "ioc_value": "digerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-06 05:36:04",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "796822": [
        {
            "ioc_value": "chitozx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-05 05:12:06",
            "last_seen_utc": "2026-08-11 03:22:20",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "",
            "tags": null,
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "750750": [
        {
            "ioc_value": "42.192.21.181:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-07-02 13:06:49",
            "last_seen_utc": "2026-08-11 03:22:09",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "730561": [
        {
            "ioc_value": "18.117.254.165:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-28 08:57:21",
            "last_seen_utc": "2026-08-11 03:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Amazon.com Inc.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "729038": [
        {
            "ioc_value": "blinkinuf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:33",
            "last_seen_utc": "2026-08-11 03:22:21",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "729037": [
        {
            "ioc_value": "malrok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-26 10:56:32",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720823": [
        {
            "ioc_value": "trumpiko.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720824": [
        {
            "ioc_value": "freygor.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-11 03:22:22",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720826": [
        {
            "ioc_value": "sinjoan.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720827": [
        {
            "ioc_value": "afluix.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 17:11:58",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720273": [
        {
            "ioc_value": "www.edge-chrome.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720276": [
        {
            "ioc_value": "www.hellomrsone.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:20",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720260": [
        {
            "ioc_value": "we.topsmartservice.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720263": [
        {
            "ioc_value": "wpsserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:19",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720248": [
        {
            "ioc_value": "thedaily-news.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:18",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720239": [
        {
            "ioc_value": "sevenhungredbucks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720241": [
        {
            "ioc_value": "snccoupr-int.cf",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720247": [
        {
            "ioc_value": "telembank.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:17",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720230": [
        {
            "ioc_value": "ppew.au",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-11 03:22:36",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720231": [
        {
            "ioc_value": "pretunz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720236": [
        {
            "ioc_value": "rss.top-business-blog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720237": [
        {
            "ioc_value": "scarfaceserver.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:16",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720226": [
        {
            "ioc_value": "outlet-studio.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:15",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720208": [
        {
            "ioc_value": "js.msedgeupdate.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:14",
            "last_seen_utc": "2026-08-11 03:21:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720198": [
        {
            "ioc_value": "harborfreight.delivery",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-11 03:22:47",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720201": [
        {
            "ioc_value": "hityok.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720203": [
        {
            "ioc_value": "jiguz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720204": [
        {
            "ioc_value": "jijuanjo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720206": [
        {
            "ioc_value": "jqueryupdatenow.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720207": [
        {
            "ioc_value": "jqueryupneed.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:13",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720188": [
        {
            "ioc_value": "fifacud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-08-11 03:22:24",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720189": [
        {
            "ioc_value": "filaspo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720193": [
        {
            "ioc_value": "gasienda.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:12",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720185": [
        {
            "ioc_value": "dreamkoks.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:11",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720176": [
        {
            "ioc_value": "democrazzy.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:54:10",
            "last_seen_utc": "2026-08-11 03:22:14",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720156": [
        {
            "ioc_value": "cloud.sovarermscloud.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:31",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720136": [
        {
            "ioc_value": "backupcreds.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720140": [
        {
            "ioc_value": "biohazzzard.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720141": [
        {
            "ioc_value": "bksfinance.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720143": [
        {
            "ioc_value": "boronab.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:28",
            "last_seen_utc": "2026-08-11 03:22:25",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720132": [
        {
            "ioc_value": "araizx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "720133": [
        {
            "ioc_value": "arminext.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-23 10:53:27",
            "last_seen_utc": "2026-08-11 03:22:26",
            "confidence_level": 50,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "719898": [
        {
            "ioc_value": "aginij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-06-22 18:35:13",
            "last_seen_utc": "2026-08-11 03:22:23",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "606362": [
        {
            "ioc_value": "criobob.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606363": [
        {
            "ioc_value": "prozakx.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606364": [
        {
            "ioc_value": "terroklo.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:58",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "606360": [
        {
            "ioc_value": "microdozz.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-19 18:01:57",
            "last_seen_utc": "2026-08-11 03:22:27",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,emotet",
            "anonymous": 0,
            "reporter": "Cryptolaemus1"
        }
    ],
    "549372": [
        {
            "ioc_value": "us189-hpgsgae5dva9fzch.z01.azurefd.net",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-10 18:53:07",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 75,
            "is_compromised": false,
            "reference": null,
            "tags": "cobaltstrike,threatview.io",
            "anonymous": 0,
            "reporter": "Malwar3Ninja"
        }
    ],
    "548951": [
        {
            "ioc_value": "artidomain.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-05-08 16:20:03",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/ian_kenefick/status/1523288477559062529",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "544836": [
        {
            "ioc_value": "116.62.185.223:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-30 19:45:18",
            "last_seen_utc": "2026-08-11 03:22:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "540702": [
        {
            "ioc_value": "165.227.180.6:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-29 19:30:18",
            "last_seen_utc": "2026-08-11 03:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "532916": [
        {
            "ioc_value": "120.26.240.21:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-25 12:31:07",
            "last_seen_utc": "2026-08-11 03:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "530098": [
        {
            "ioc_value": "193.29.13.216:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-23 16:42:50",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "***************************************,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "523516": [
        {
            "ioc_value": "45.8.158.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-21 16:54:57",
            "last_seen_utc": "2026-08-11 03:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASBAXETN,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521565": [
        {
            "ioc_value": "115.29.171.175:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-19 13:44:33",
            "last_seen_utc": "2026-08-11 03:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "521083": [
        {
            "ioc_value": "84.32.188.190:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-18 18:01:52",
            "last_seen_utc": "2026-08-11 03:22:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "520317": [
        {
            "ioc_value": "137.184.42.85:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-15 22:57:51",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519914": [
        {
            "ioc_value": "84.32.188.104:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 16:59:25",
            "last_seen_utc": "2026-08-11 03:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,UAB Cherry Servers",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "519792": [
        {
            "ioc_value": "furfen.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-14 10:30:57",
            "last_seen_utc": "2026-08-11 03:22:28",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "BumbleBee,Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "519116": [
        {
            "ioc_value": "175.41.21.29:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-13 16:57:52",
            "last_seen_utc": "2026-08-11 03:22:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518853": [
        {
            "ioc_value": "175.41.16.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-12 16:50:58",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,XLC-AS-AP XLC GLOBAL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "518404": [
        {
            "ioc_value": "138.68.110.227:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-10 17:05:31",
            "last_seen_utc": "2026-08-11 03:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "516676": [
        {
            "ioc_value": "13.55.118.253:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-06 22:59:35",
            "last_seen_utc": "2026-08-11 03:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AMAZON-02,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "493695": [
        {
            "ioc_value": "185.186.143.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 22:55:20",
            "last_seen_utc": "2026-08-11 03:22:31",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ASKONTEL,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "492845": [
        {
            "ioc_value": "194.37.97.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-04-05 16:53:16",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247 Ltd",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "466600": [
        {
            "ioc_value": "blopik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-30 09:51:36",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "461231": [
        {
            "ioc_value": "borizhog.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-29 08:36:59",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "448027": [
        {
            "ioc_value": "37.72.172.110:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 22:55:12",
            "last_seen_utc": "2026-08-11 03:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "446029": [
        {
            "ioc_value": "1.14.76.111:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-24 10:56:07",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443786": [
        {
            "ioc_value": "139.60.160.8:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 20:44:05",
            "last_seen_utc": "2026-08-11 03:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HOSTKEY-USA",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "443190": [
        {
            "ioc_value": "apeduze.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-23 16:44:21",
            "last_seen_utc": "2026-08-11 03:22:29",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438442": [
        {
            "ioc_value": "drimzis.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "438443": [
        {
            "ioc_value": "blinkij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-22 10:51:28",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "398650": [
        {
            "ioc_value": "152.136.178.142:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 22:47:07",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "396104": [
        {
            "ioc_value": "dunclikf.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-17 12:19:46",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393426": [
        {
            "ioc_value": "sifgu.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393427": [
        {
            "ioc_value": "gfsert.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-11 03:22:40",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393429": [
        {
            "ioc_value": "shizij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393430": [
        {
            "ioc_value": "zxerm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393431": [
        {
            "ioc_value": "korunder.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:52",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393424": [
        {
            "ioc_value": "chesft.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393425": [
        {
            "ioc_value": "uktyl.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-10 15:29:51",
            "last_seen_utc": "2026-08-11 03:22:39",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": null,
            "anonymous": 0,
            "reporter": "stoerchl"
        }
    ],
    "393312": [
        {
            "ioc_value": "defenr.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393313": [
        {
            "ioc_value": "fedij.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393314": [
        {
            "ioc_value": "kejimn.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:35",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393311": [
        {
            "ioc_value": "brikeb.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-09 17:18:34",
            "last_seen_utc": "2026-08-11 03:22:43",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "393046": [
        {
            "ioc_value": "kapuleti.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-08 17:09:32",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "392705": [
        {
            "ioc_value": "45.12.1.24:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-06 16:43:33",
            "last_seen_utc": "2026-08-11 03:22:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392630": [
        {
            "ioc_value": "45.12.1.25:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:45:53",
            "last_seen_utc": "2026-08-11 03:22:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YURTEH-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "392595": [
        {
            "ioc_value": "45.12.1.26:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-05 16:43:28",
            "last_seen_utc": "2026-08-11 03:22:30",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CLOUDNETWORKS-AS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "391528": [
        {
            "ioc_value": "defegh.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391530": [
        {
            "ioc_value": "klycnmik.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391531": [
        {
            "ioc_value": "ngrety.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-03-01 07:06:28",
            "last_seen_utc": "2026-08-11 03:22:44",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "391111": [
        {
            "ioc_value": "lifegothistory.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-27 06:03:58",
            "last_seen_utc": "2026-08-11 03:22:45",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1497771037718724612",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "390123": [
        {
            "ioc_value": "192.241.133.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:44:41",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "390104": [
        {
            "ioc_value": "159.65.246.188:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-22 16:42:29",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389873": [
        {
            "ioc_value": "68.183.200.63:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:58:18",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389866": [
        {
            "ioc_value": "138.68.227.71:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:57:13",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389865": [
        {
            "ioc_value": "165.227.219.211:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:56:32",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389864": [
        {
            "ioc_value": "165.232.154.73:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:55:44",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389861": [
        {
            "ioc_value": "143.198.110.248:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:53",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389860": [
        {
            "ioc_value": "178.128.171.206:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:54:15",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389853": [
        {
            "ioc_value": "165.227.23.218:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:53:10",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389850": [
        {
            "ioc_value": "161.35.137.163:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:52:19",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389847": [
        {
            "ioc_value": "64.227.0.177:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-21 16:51:26",
            "last_seen_utc": "2026-08-11 03:22:42",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "389656": [
        {
            "ioc_value": "45.55.36.143:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-20 16:42:59",
            "last_seen_utc": "2026-08-11 03:22:41",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,DIGITALOCEAN-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "384626": [
        {
            "ioc_value": "168.61.180.98:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-09 22:36:37",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,MICROSOFT-CORP-MSN-AS-BLOCK",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "373668": [
        {
            "ioc_value": "bornometa.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373671": [
        {
            "ioc_value": "jenevabaiden.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-08-11 03:22:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "373673": [
        {
            "ioc_value": "sbronm.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-02-01 10:45:03",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/1ZRR4H/status/1488311508652204037",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "362296": [
        {
            "ioc_value": "101.34.182.130:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-29 22:33:30",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332687": [
        {
            "ioc_value": "192.227.155.185:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:30:16",
            "last_seen_utc": "2026-08-11 03:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "332653": [
        {
            "ioc_value": "146.70.29.233:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-25 22:29:00",
            "last_seen_utc": "2026-08-11 03:22:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,M247",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "313943": [
        {
            "ioc_value": "107.172.219.129:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-22 22:25:42",
            "last_seen_utc": "2026-08-11 03:22:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "299262": [
        {
            "ioc_value": "193.201.9.229:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 22:32:52",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,SELECTEL",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "298501": [
        {
            "ioc_value": "citrixseruritys.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "298505": [
        {
            "ioc_value": "milanvar.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-18 13:51:16",
            "last_seen_utc": "2026-08-11 03:22:51",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/MichalKoczwara/status/1483137082465865729",
            "tags": "Cobalt Strike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "295525": [
        {
            "ioc_value": "23.227.198.246:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 22:26:20",
            "last_seen_utc": "2026-08-11 03:22:49",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295436": [
        {
            "ioc_value": "217.79.243.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-15 10:32:22",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "295353": [
        {
            "ioc_value": "149.255.35.131:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-14 22:28:25",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HVC-AS",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "294999": [
        {
            "ioc_value": "81.68.225.136:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-13 22:28:33",
            "last_seen_utc": "2026-08-11 03:22:32",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "292303": [
        {
            "ioc_value": "39.98.48.153:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-10 16:24:49",
            "last_seen_utc": "2026-08-11 03:21:07",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "291740": [
        {
            "ioc_value": "39.104.25.164:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2022-01-07 10:30:52",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "276593": [
        {
            "ioc_value": "77.83.36.54:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-16 10:42:30",
            "last_seen_utc": "2026-08-11 03:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,ISI-ASN",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "275144": [
        {
            "ioc_value": "101.32.204.81:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-12-13 10:06:28",
            "last_seen_utc": "2026-08-11 03:22:37",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TENCENT-NET-AP-CN Tencent Building Kejizhongyi Avenue",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "252110": [
        {
            "ioc_value": "62.113.255.12:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-22 16:01:01",
            "last_seen_utc": "2026-08-11 03:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,TTM",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "242948": [
        {
            "ioc_value": "107.173.89.148:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-11-04 17:48:48",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "AS-COLOCROSSING,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "240983": [
        {
            "ioc_value": "104.128.92.144:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-31 17:43:37",
            "last_seen_utc": "2026-08-11 03:22:50",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,IT7NET",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "238207": [
        {
            "ioc_value": "fivepointschiro.com",
            "ioc_type": "domain",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-27 09:58:20",
            "last_seen_utc": "2026-08-11 03:22:46",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": "https://twitter.com/mojoesec/status/1453040284686770185",
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "abuse_ch"
        }
    ],
    "236436": [
        {
            "ioc_value": "111.230.196.200:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-22 12:07:15",
            "last_seen_utc": "2026-08-11 03:22:35",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "233476": [
        {
            "ioc_value": "23.224.152.139:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-13 17:43:22",
            "last_seen_utc": "2026-08-11 03:22:33",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNSERVERS,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232821": [
        {
            "ioc_value": "139.198.183.44:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-11 23:27:10",
            "last_seen_utc": "2026-08-11 03:22:34",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,YUNIFY-NET Yunify Technologies Inc.",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "232263": [
        {
            "ioc_value": "121.37.255.60:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-10-09 23:36:53",
            "last_seen_utc": "2026-08-11 03:22:38",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CobaltStrike,HWCSNET Huawei Cloud Service data center",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ],
    "223357": [
        {
            "ioc_value": "47.95.207.79:443",
            "ioc_type": "ip:port",
            "threat_type": "botnet_cc",
            "malware": "win.cobalt_strike",
            "malware_alias": "Agentemis,BEACON,CobaltStrike,cobeacon",
            "malware_printable": "Cobalt Strike",
            "first_seen_utc": "2021-09-18 17:39:24",
            "last_seen_utc": "2026-08-11 03:22:36",
            "confidence_level": 100,
            "is_compromised": false,
            "reference": null,
            "tags": "CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.Ltd.,CobaltStrike",
            "anonymous": 0,
            "reporter": "drb_ra"
        }
    ]
}